auth.c in LibVNCServer 0.7.1 allows remote attackers to bypass authentication via a request in which the client specifies an insecure security type such as Type 1 - None, which is accepted even if it is not offered by the server, a different issue than CVE-2006-2369.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Libvncserver | Libvncserver | 0.7.1 (including) | 0.7.1 (including) |
Libvncserver | Ubuntu | dapper | * |
Libvncserver | Ubuntu | upstream | * |