Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

Mageia 7: 2021-0016 Moderate: XRDP Denial Of Service Risk

mageia
Calendar Grey January 10, 2021
Dist Mageia Esm H88
Fedora's recent patch release tackles a severe vulnerability in the OpenSSH configuration, enhancing the protection of remote login details.
Ashley Newson discovered that the XRDP sessions manager was susceptible to denial of service

Summary

Ashley Newson discovered that the XRDP sessions manager was susceptible to denial of service. A local attacker can further take advantage of this flaw to impersonate the XRDP sessions manager and capture any user credentials that are submitted to XRDP, approve or reject arbitrary login credentials or to hijack existing sessions for xorgxrdp sessions (CVE-2020-4044).

References

- https://bugs.mageia.org/show_bug.cgi?id=26931

- https://lists.debian.org/debian-security-announce/2020/msg00143.html

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/7FYD6USHZXDI2EAZVGOVFMAE7ILP3SPL/

- https://www.cve.org/CVERecord?id=CVE-2020-4044

Resolution

SRPMS

- 7/core/xrdp-0.9.10-1.1.mga7

Publication date: 10 Jan 2021
URL: https://advisories.mageia.org/MGASA-2021-0016.html
Type: security
CVE: CVE-2020-4044

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here