Short Name |
VNC:INVALID:CLIENT-VERSION |
---|---|
Severity |
Low |
Recommended |
No |
Category |
VNC |
Release Date |
2003/04/22 |
Update Number |
1213 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This protocol anomaly triggers when it detects a VNC client message that has an invalid version string. The VNC protocol defines valid VNC version syntax as RFB xxx.yyy\n. With (xxx) representing major version numbers and (yyy) representing minor version numbers; this is padded with zeros and followed by a NULL character.
If a ProtocolVersion message does not comply with the standard format, this may indicate that a software or transmission error has occurred. It may also indicate that a malicious party is attempting to conduct a buffer overflow or other attack against a VNC client or server.