Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

SUSE: 2019:1847-1 Important: xrdp Security Issues Fixed

suse
Calendar Grey July 15, 2019
Dist Suse Esm H88
Crucial SUSE Safety Patch for xrdp addresses multiple vulnerabilities and offers installation instructions.
An update that solves three vulnerabilities and has 5 fixes is now available

Summary

This update for xrdp fixes the following issues: These security issues were fixed: - CVE-2013-1430: When successfully logging in using RDP into an xrdp session, the file ~/.vnc/sesman_${username}_passwd was created. Its content was the equivalent of the user's cleartext password, DES encrypted with a known key (bsc#1015567). - CVE-2017-16927: The scp_v0s_accept function in sesman/libscp/libscp_v0.c in the session manager in xrdp through used an untrusted integer as a write length, which could lead to a local denial of service (bsc#1069591). - CVE-2017-6967: Fixed call of the PAM function auth_start_session(). This lead to to PAM session modules not being properly initialized, with a potential consequence of incorrect configurations or elevation of privileges, aka a pam_limits.so bypass (bsc#1029912).

References

#1014524 #1015567 #1029912 #1060644 #1069591

#1090174 #1100453 #1101506

Cross- CVE-2013-1430 CVE-2017-16927 CVE-2017-6967

Affected Products:

SUSE Linux Enterprise Server 12-SP4

SUSE Linux Enterprise Desktop 12-SP4

https://www.suse.com/security/cve/CVE-2013-1430.html

https://www.suse.com/security/cve/CVE-2017-16927.html

https://www.suse.com/security/cve/CVE-2017-6967.html

https://bugzilla.suse.com/1014524

https://bugzilla.suse.com/1015567

https://bugzilla.suse.com/1029912

https://bugzilla.suse.com/1060644

https://bugzilla.suse.com/1069591

https://bugzilla.suse.com/1090174

https://bugzilla.suse.com/1100453

https://bugzilla.suse.com/1101506

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2019:1847-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here