Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Fedora 26: 2017-4603342f9a Critical xrdp Denial Of Service Issue

fedora
Calendar Grey January 9, 2018
Dist Fedora Esm H88
Essential security patch for xrdp in Fedora tackles service disruption vulnerabilities while bringing in enhanced functionalities and resolving existing issues.
Security fixes - Fix local denial of service CVE-2017-16927 #958 #979 (fix already in 0.9.4-2) New features - Add a new log level TRACE more verbose than DEBUG #835 #944 - SSH agen...

Summary

xrdp provides a fully functional RDP server compatible with a wide range

of RDP clients, including FreeRDP and Microsoft RDP client.

Security fixes - Fix local denial of service CVE-2017-16927 #958 #979 (fix

already in 0.9.4-2) New features - Add a new log level TRACE more verbose than

DEBUG #835 #944 - SSH agent forwarding via RDP #867 #868 FreeRDP/FreeRDP#4122 -Support horizontal wheel properly #928 Bug fixes - Avoid use of hard-coded

sesman port #895 - Workaround for corrupted display with Windows Server 2008

using NeutrinoRDP #869 - Fix glitch in audio redirection by AAC #910 #936 -Implement vsock support #930 #935 #948 - Avoid 100% CPU usage on SSL accept #956

Other changes - Add US Dvorak keyboard #929 - Suppress some misleading logs

#964 - Add Finnish keyboard #972 - Add more user-friendlier description about

Xorg config #974 - Renew pulseaudio document #984 #985 - Lots of cleanups and

refactoring Known issues - Audio redirection by MP3 codec doesn't sound with

some client, use AAC instead #965

[ 1 ] Bug #1516760 - CVE-2017-16927 xrdp: Buffer-overflow in scp_v0s_accept function in session manager [epel-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1516760

su -c 'dnf upgrade xrdp' at the command line.

For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 26
Version: 0.9.5
Release: 1.fc26
Summary: Open source remote desktop protocol (RDP) server

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here