CVE Vulnerabilities

CVE-2002-1511

Published: Mar 03, 2003 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The vncserver wrapper for vnc before 3.3.3r2-21 uses the rand() function instead of srand(), which causes vncserver to generate weak cookies.

Affected Software

NameVendorStart VersionEnd Version
VncAtt3.3.3 (including)3.3.3 (including)
VncAtt3.3.3r2 (including)3.3.3r2 (including)
VncAtt3.3.4 (including)3.3.4 (including)
VncAtt3.3.5 (including)3.3.5 (including)
VncAtt3.3.6 (including)3.3.6 (including)
TightvncTightvnc1.2.0 (including)1.2.0 (including)
TightvncTightvnc1.2.1 (including)1.2.1 (including)
TightvncTightvnc1.2.2 (including)1.2.2 (including)
TightvncTightvnc1.2.3 (including)1.2.3 (including)
TightvncTightvnc1.2.4 (including)1.2.4 (including)
TightvncTightvnc1.2.5 (including)1.2.5 (including)
Red Hat Enterprise Linux AS (Advanced Server) version 2.1RedHat*
Red Hat Linux 7.0RedHat*
Red Hat Linux 7.1RedHat*
Red Hat Linux 7.2RedHat*
Red Hat Linux 7.3RedHat*
Red Hat Linux 8.0RedHat*

References