Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Mageia: 2023-0276 Moderate: Xrdp Session Handling Bypass Risk

mageia
Calendar Grey September 30, 2023
Dist Mageia Esm H88
Latest xrdp updates in Mageia address session management challenges, rectifying significant circumvention of operating system security measures.
In versions prior to 0.9.23 improper handling of session establishment errors allows bypassing OS-level session restrictions

Summary

In versions prior to 0.9.23 improper handling of session establishment errors allows bypassing OS-level session restrictions. The `auth_start_session` function can return non-zero (1) value on, e.g., PAM error which may result in in session restrictions such as max concurrent sessions per user by PAM (ex ./etc/security/limits.conf) to be bypassed. (CVE-2023-40184)

References

- https://bugs.mageia.org/show_bug.cgi?id=32276

- https://www.cve.org/CVERecord?id=CVE-2023-40184

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SOT237TIHTHPX5YNIWLVNINOEYC7WMG2/

- https://www.cve.org/CVERecord?id=CVE-2023-40184

Resolution

SRPMS

- 8/core/xrdp-0.9.23-1.mga8

- 9/core/xrdp-0.9.23-1.mga9

Publication date: 30 Sep 2023
URL: https://advisories.mageia.org/MGASA-2023-0276.html
Type: security
CVE: CVE-2023-40184

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here