---------------------------------------------------------------------- Bist Du interessiert an einem neuen Job in IT-Sicherheit? Secunia hat zwei freie Stellen als Junior und Senior Spezialist in IT- Sicherheit: http://secunia.com/secunia_vacancies/ ---------------------------------------------------------------------- TITLE: RealVNC Information Disclosure Weakness SECUNIA ADVISORY ID: SA15742 VERIFY ADVISORY: http://secunia.com/advisories/15742/ CRITICAL: Not critical IMPACT: Exposure of system information WHERE: >From remote SOFTWARE: RealVNC 4.x http://secunia.com/product/3719/ DESCRIPTION: class101 has reported a weakness in RealVNC, which can be exploited by malicious people to gain knowledge of various system information. The weakness is caused due to different versions responding differently to requests. This can be exploited to disclose the edition of RealVNC that is running and the OS (Operating System) type. SOLUTION: Filter incoming VNC traffic at the firewall. PROVIDED AND/OR DISCOVERED BY: class101 ORIGINAL ADVISORY: http://www.realvnc.com/pipermail/vnc-list/2005-June/051336.html ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help everybody keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ----------------------------------------------------------------------