Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Ubuntu 22.04 LTS USN-6474-1 Critical: xrdp Out-of-Bounds Issues

ubuntu
Calendar Grey November 9, 2023
Dist Ubuntu Esm H88
Urgent security concerns with xrdp necessitate immediate updates for Ubuntu users. Address vulnerabilities promptly to improve safety.
Several security issues were fixed in xrdp.

Summary

A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS (Available with Ubuntu Pro) - Ubuntu 20.04 LTS (Available with Ubuntu Pro) - Ubuntu 18.04 LTS (Available with Ubuntu Pro) - Ubuntu 16.04 LTS (Available with Ubuntu Pro) - Ubuntu 14.04 LTS (Available with Ubuntu Pro) Summary: Several security issues were fixed in xrdp. Software Description: - xrdp: Remote Desktop Protocol (RDP) server Details: It was discovered that xrdp incorrectly handled validation of client-supplied data, which could lead to out-of-bounds reads. An attacker could possibly use this issue to crash the program or extract sensitive information. (CVE-2022-23479, CVE-2022-23481, CVE-2022-23483, CVE-2023-42822) It was discovered that xrdp improperly handled session establishment errors. An attacker could potentially use this issue to bypass the OS-level session restrictions by PAM. (CVE-2023-40184) It was discovered that xrdp incorrectly handled...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS (Available with Ubuntu Pro): xrdp 0.9.17-2ubuntu2+esm1 Ubuntu 20.04 LTS (Available with Ubuntu Pro): xrdp 0.9.12-1ubuntu0.1+esm1 Ubuntu 18.04 LTS (Available with Ubuntu Pro): xrdp 0.9.5-2ubuntu0.1~esm2 Ubuntu 16.04 LTS (Available with Ubuntu Pro): xrdp 0.6.1-2ubuntu0.3+esm3 Ubuntu 14.04 LTS (Available with Ubuntu Pro): xrdp 0.6.0-1ubuntu0.1+esm3 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-6474-1

CVE-2022-23468, CVE-2022-23477, CVE-2022-23478, CVE-2022-23479,

CVE-2022-23480, CVE-2022-23481, CVE-2022-23482, CVE-2022-23483,

CVE-2022-23484, CVE-2022-23493, CVE-2022-23613, CVE-2023-40184,

CVE-2023-42822

Severity
critical
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-6474-1

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here