Updates/vnc-4.1.1-11.fc4
From FarsiWeb
The vnc and vnc-server packages contain a remote display system called Virtual Network Computing (VNC) client and server which allow you to view a desktop environment not only on the machine where it is running, but from anywhere on the Internet.
This update fixes the Common Vulnerabilities and Exposures issue CVE 2006-2369:
- RealVNC 4.1.1, and other products that use RealVNC such as AdderLink IP, allows remote attackers to bypass authentication via a request in which the client specifies an insecure security type such as
"Type 1 - None", which is accepted even if it is not offered by the server, as originally demonstrated using a long password.
This update includes a patch that fixes the above-mentioned possible authentication bypassing.
