--------------------------------------------------------------------------------Fedora Update Notification
FEDORA-2022-08d2138578
2022-12-21 01:17:10.825361
--------------------------------------------------------------------------------Name        : xrdp
Product     : Fedora 36
Version     : 0.9.21
Release     : 1.fc36
URL         : http://www.xrdp.org/
Summary     : Open source remote desktop protocol (RDP) server
Description :
xrdp provides a fully functional RDP server compatible with a wide range
of RDP clients, including FreeRDP and Microsoft RDP client.

--------------------------------------------------------------------------------Update Information:

Release notes for xrdp v0.9.21 (2022/12/10)  General announcements  - Running
xrdp and xrdp-sesman on separate hosts is still supported by this release, but
is now deprecated. This is not secure. A future v1.0 release will replace the
TCP socket used between these processes with a Unix Domain Socket, and then
cross-host running will not be possible.  Security fixes  This update is
recommended for all xrdp users and provides following important security fixes:
- CVE-2022-23468 - CVE-2022-23477 - CVE-2022-23478 - CVE-2022-23479 -CVE-2022-23480 - CVE-2022-23481 - CVE-2022-23483 - CVE-2022-23482 -CVE-2022-23484 - CVE-2022-23493  These security issues are reported by Team BT5
(BoB 11th). We appreciate their great help with making and reviewing patches.
New features  - openSuSE Tumbleweed move to /usr/lib/pam.d is now supported in
the installation scripts (#2413) - VNC backend session now supports extra mouse
buttons 6, 7 and 8 (#2426)  Bug fixes  - Passwords are no longer left on the
heap in sesman (#1599 #2439) - Set permissions on pcsc socket dir to owner only
(#2454 #2460)  Internal changes  - CI updates to cope with github upgrades
(#2395)  Changes for packagers or developers  Nothing this time.  Known issues
- On-the-fly resolution change requires the Microsoft Store version of Remote
Desktop client but sometimes crashes on connect (#1869) - xrdp's login dialog is
not relocated at the center of the new resolution after on-the-fly resolution
change happens (#1867)
--------------------------------------------------------------------------------ChangeLog:

* Sun Dec 11 2022 Bojan Smojver  - 1:0.9.21-1
- Bump up to 0.9.21
--------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2022-08d2138578' at the command
line. For more information, refer to the dnf documentation available at
https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/security/
--------------------------------------------------------------------------------_______________________________________________
package-announce mailing list -- package-announce@lists.fedoraproject.org
To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/
Do not reply to spam, report it: https://pagure.io/login/

Fedora 36: xrdp 2022-08d2138578

December 21, 2022
Release notes for xrdp v0.9.21 (2022/12/10) General announcements - Running xrdp and xrdp-sesman on separate hosts is still supported by this release, but is now deprecated

Summary

xrdp provides a fully functional RDP server compatible with a wide range

of RDP clients, including FreeRDP and Microsoft RDP client.

Release notes for xrdp v0.9.21 (2022/12/10) General announcements - Running

xrdp and xrdp-sesman on separate hosts is still supported by this release, but

is now deprecated. This is not secure. A future v1.0 release will replace the

TCP socket used between these processes with a Unix Domain Socket, and then

cross-host running will not be possible. Security fixes This update is

recommended for all xrdp users and provides following important security fixes:

- CVE-2022-23468 - CVE-2022-23477 - CVE-2022-23478 - CVE-2022-23479 -CVE-2022-23480 - CVE-2022-23481 - CVE-2022-23483 - CVE-2022-23482 -CVE-2022-23484 - CVE-2022-23493 These security issues are reported by Team BT5

(BoB 11th). We appreciate their great help with making and reviewing patches.

New features - openSuSE Tumbleweed move to /usr/lib/pam.d is now supported in

the installation scripts (#2413) - VNC backend session now supports extra mouse

buttons 6, 7 and 8 (#2426) Bug fixes - Passwords are no longer left on the

heap in sesman (#1599 #2439) - Set permissions on pcsc socket dir to owner only

(#2454 #2460) Internal changes - CI updates to cope with github upgrades

(#2395) Changes for packagers or developers Nothing this time. Known issues

- On-the-fly resolution change requires the Microsoft Store version of Remote

Desktop client but sometimes crashes on connect (#1869) - xrdp's login dialog is

not relocated at the center of the new resolution after on-the-fly resolution

change happens (#1867)

* Sun Dec 11 2022 Bojan Smojver - 1:0.9.21-1

- Bump up to 0.9.21

su -c 'dnf upgrade --advisory FEDORA-2022-08d2138578' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Do not reply to spam, report it: https://pagure.io/login/

FEDORA-2022-08d2138578 2022-12-21 01:17:10.825361 Product : Fedora 36 Version : 0.9.21 Release : 1.fc36 URL : http://www.xrdp.org/ Summary : Open source remote desktop protocol (RDP) server Description : xrdp provides a fully functional RDP server compatible with a wide range of RDP clients, including FreeRDP and Microsoft RDP client. Release notes for xrdp v0.9.21 (2022/12/10) General announcements - Running xrdp and xrdp-sesman on separate hosts is still supported by this release, but is now deprecated. This is not secure. A future v1.0 release will replace the TCP socket used between these processes with a Unix Domain Socket, and then cross-host running will not be possible. Security fixes This update is recommended for all xrdp users and provides following important security fixes: - CVE-2022-23468 - CVE-2022-23477 - CVE-2022-23478 - CVE-2022-23479 -CVE-2022-23480 - CVE-2022-23481 - CVE-2022-23483 - CVE-2022-23482 -CVE-2022-23484 - CVE-2022-23493 These security issues are reported by Team BT5 (BoB 11th). We appreciate their great help with making and reviewing patches. New features - openSuSE Tumbleweed move to /usr/lib/pam.d is now supported in the installation scripts (#2413) - VNC backend session now supports extra mouse buttons 6, 7 and 8 (#2426) Bug fixes - Passwords are no longer left on the heap in sesman (#1599 #2439) - Set permissions on pcsc socket dir to owner only (#2454 #2460) Internal changes - CI updates to cope with github upgrades (#2395) Changes for packagers or developers Nothing this time. Known issues - On-the-fly resolution change requires the Microsoft Store version of Remote Desktop client but sometimes crashes on connect (#1869) - xrdp's login dialog is not relocated at the center of the new resolution after on-the-fly resolution change happens (#1867) * Sun Dec 11 2022 Bojan Smojver - 1:0.9.21-1 - Bump up to 0.9.21 su -c 'dnf upgrade --advisory FEDORA-2022-08d2138578' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ package-announce mailing list -- package-announce@lists.fedoraproject.org To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/ Do not reply to spam, report it: https://pagure.io/login/

Change Log

References

Update Instructions

Severity
Product : Fedora 36
Version : 0.9.21
Release : 1.fc36
URL : http://www.xrdp.org/
Summary : Open source remote desktop protocol (RDP) server

Related News