Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Debian LTS: DLA-4166-1 critical: xrdp session management flaws

debian lts
Calendar Grey May 16, 2025
Dist Debian Esm H88
Explore Debian LTS Advisory DLA-4166-1 detailing critical security updates for xrdp, focusing on resolved vulnerabilities for secure remote sessions and stability
Several vulnerabilities were discovered in xrdp, a Remote Desktop Protocol (RDP) server

Summary


CVE-2023-40184

improper handling of session establishment errors allows bypassing
OS-level session restrictions. The `auth_start_session` function
can return non-zero on PAM error which may result in in session
restrictions such as max concurrent sessions per user by PAM.

CVE-2023-42822

Access to the font glyphs in xrdp_painter.c is not bounds-checked
. Since some of this data is controllable by the user, this can
result in an out-of-bounds read within the xrdp executable. The
vulnerability allows an out-of-bounds read within a potentially
privileged process.

CVE-2024-39917

a vulnerability that allows attackers to make an infinite number
of login attempts. The number of max login attempts is supposed to
be limited by a configuration parameter `MaxLoginRetry` in
`/etc/xrdp/sesman.ini`. However, this mechanism was not
effectively working. As a result, xrdp allows an infinite number
of login attempts.

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: xrdp
Version: 0.9.21.1-1~deb11u2
CVE ID: CVE-2023-40184 CVE-2023-42822 CVE-2024-39917

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here