Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Debian 10: DLA-3370-1 Moderate: xrdp Memory Access and Buffer Overflows

debian lts
Calendar Grey March 30, 2023
Dist Debian Esm H88
Debian LTS Advisory DLA-3371-1 pertains to security patches for libpng, which includes critical vulnerabilities related to memory corruption and potential denial of service scenarios.
Several out of bounds memory access and buffer overflows were fixed in xrdp, an open source project which provides a graphical login to remote machines using Microsoft Remote Deskt...

Summary

xrdp < v0.9.21 contain a buffer over flow in xrdp_login_wnd_create() function.
There are no known workarounds for this issue.

CVE-2022-23478

xrdp < v0.9.21 contain a Out of Bound Write in
xrdp_mm_trans_process_drdynvc_channel_open() function. There are no known
workarounds for this issue.

CVE-2022-23479

xrdp < v0.9.21 contain a buffer over flow in xrdp_mm_chan_data_in() function.
There are no known workarounds for this issue.

CVE-2022-23483

xrdp < v0.9.21 contain a Out of Bound Read in libxrdp_send_to_channel() function.
There are no known workarounds for this issue.

CVE-2022-23484

xrdp < v0.9.21 contain a Integer Overflow in xrdp_mm_process_rail_update_window_text()
function. There are no known workarounds for this issue.

CVE-2022-23493

xrdp < v0.9.21 contain a Out of Bound Read in xrdp_mm_trans_process_drdynvc_channel_close()
function. There are no known workarounds for this issue.

Read the Full Advisory


-------------------------------------------------------------------------Package: xrdp
Version: 0.9.9-1+deb10u2
CVE ID: CVE-2022-23468 CVE-2022-23478 CVE-2022-23479 CVE-2022-23483
Debian Bug:

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here