Search CVE reports
11 – 20 of 22 results
CVE-2022-23478
Medium prioritySome fixes available 2 of 3
xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a Out of Bound Write in xrdp_mm_trans_process_drdynvc_channel_open()...
1 affected packages
xrdp
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
xrdp | Not affected | Fixed | Fixed | Not affected | Not affected |
CVE-2022-23477
Medium prioritySome fixes available 2 of 3
xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a buffer over flow in audin_send_open() function. There are no known...
1 affected packages
xrdp
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
xrdp | Not affected | Fixed | Fixed | Not affected | Not affected |
CVE-2022-23468
Medium prioritySome fixes available 3 of 4
xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a buffer over flow in xrdp_login_wnd_create() function. There are no known...
1 affected packages
xrdp
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
xrdp | Not affected | Fixed | Fixed | Fixed | Not affected |
CVE-2022-23613
Medium prioritySome fixes available 5 of 11
xrdp is an open source remote desktop protocol (RDP) server. In affected versions an integer underflow leading to a heap overflow in the sesman server allows any unauthenticated attacker which is able to locally access a sesman...
1 affected packages
xrdp
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
xrdp | Needs evaluation | Fixed | Fixed | Fixed | Fixed |
CVE-2021-36158
Medium priorityIn the xrdp package (in branches through 3.14) for Alpine Linux, RDP sessions are vulnerable to man-in-the-middle attacks because pre-generated RSA certificates and private keys are used.
1 affected packages
xrdp
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
xrdp | — | Not affected | Not affected | Not affected | Not affected |
CVE-2020-4044
Medium prioritySome fixes available 4 of 5
The xrdp-sesman service before version 0.9.13.1 can be crashed by connecting over port 3350 and supplying a malicious payload. Once the xrdp-sesman process is dead, an unprivileged attacker on the server could then proceed to...
1 affected packages
xrdp
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
xrdp | — | Not affected | Fixed | Fixed | Fixed |
CVE-2017-16927
Medium prioritySome fixes available 2 of 4
The scp_v0s_accept function in sesman/libscp/libscp_v0.c in the session manager in xrdp through 0.9.4 uses an untrusted integer as a write length, which allows local users to cause a denial of service (buffer overflow...
1 affected packages
xrdp
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
xrdp | — | Not affected | Not affected | Not affected | Fixed |
CVE-2017-6967
Medium prioritySome fixes available 3 of 6
xrdp 0.9.1 calls the PAM function auth_start_session() in an incorrect location, leading to PAM session modules not being properly initialized, with a potential consequence of incorrect configurations or elevation of privileges,...
1 affected packages
xrdp
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
xrdp | — | Not affected | Not affected | Not affected | Fixed |
CVE-2013-1430
Medium prioritySome fixes available 2 of 6
An issue was discovered in xrdp before 0.9.1. When successfully logging in using RDP into an xrdp session, the file ~/.vnc/sesman_${username}_passwd is created. Its content is the equivalent of the user's cleartext password, DES...
1 affected packages
xrdp
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
xrdp | — | — | — | Not affected | Fixed |
CVE-2008-5904
Medium priorityThe rdp_rdp_process_color_pointer_pdu function in rdp/rdp_rdp.c in xrdp 0.4.1 and earlier allows remote RDP servers to have an unknown impact via input data that sets crafted values for certain length variables, leading to a...
1 affected packages
xrdp
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
xrdp | — | — | — | — | — |