* bsc#1215803 Cross-References: * CVE-2023-42822 . # Security update for xrdp Announcement ID: SUSE-SU-2023:4577-1 Rating: moderate References: * bsc#1215803 Cross-References: * CVE-2023-42822 CVSS scores: * CVE-2023-42822 ( SUSE ): 4.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N * CVE-2023-42822 ( NVD ): 4.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N Affected Products: * Basesystem Module 15-SP4 * Basesystem Module 15-SP5 * openSUSE Leap 15.4 * openSUSE Leap 15.5 * SUSE Linux Enterprise Desktop 15 SP4 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves one vulnerability can now be installed. ## Description: This update for xrdp fixes the following issues: * CVE-2023-42822: Fixed unchecked access to font glyph info (bsc#1215803). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch openSUSE-SLE-15.4-2023-4577=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2023-4577=1 * Basesystem Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP4-2023-4577=1 * Basesystem Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP5-2023-4577=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64) * libpainter0-0.9.13.1-150200.4.27.1 * xrdp-debuginfo-0.9.13.1-150200.4.27.1 *xrdp-devel-0.9.13.1-150200.4.27.1 * libpainter0-debuginfo-0.9.13.1-150200.4.27.1 * librfxencode0-debuginfo-0.9.13.1-150200.4.27.1 * xrdp-debugsource-0.9.13.1-150200.4.27.1 * xrdp-0.9.13.1-150200.4.27.1 * librfxencode0-0.9.13.1-150200.4.27.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * libpainter0-0.9.13.1-150200.4.27.1 * xrdp-debuginfo-0.9.13.1-150200.4.27.1 * xrdp-devel-0.9.13.1-150200.4.27.1 * libpainter0-debuginfo-0.9.13.1-150200.4.27.1 * librfxencode0-debuginfo-0.9.13.1-150200.4.27.1 * xrdp-debugsource-0.9.13.1-150200.4.27.1 * xrdp-0.9.13.1-150200.4.27.1 * librfxencode0-0.9.13.1-150200.4.27.1 * Basesystem Module 15-SP4 (aarch64 ppc64le s390x x86_64) * libpainter0-0.9.13.1-150200.4.27.1 * xrdp-debuginfo-0.9.13.1-150200.4.27.1 * xrdp-devel-0.9.13.1-150200.4.27.1 * libpainter0-debuginfo-0.9.13.1-150200.4.27.1 * librfxencode0-debuginfo-0.9.13.1-150200.4.27.1 * xrdp-debugsource-0.9.13.1-150200.4.27.1 * xrdp-0.9.13.1-150200.4.27.1 * librfxencode0-0.9.13.1-150200.4.27.1 * Basesystem Module 15-SP5 (aarch64 ppc64le s390x x86_64) * libpainter0-0.9.13.1-150200.4.27.1 * xrdp-debuginfo-0.9.13.1-150200.4.27.1 * xrdp-devel-0.9.13.1-150200.4.27.1 * libpainter0-debuginfo-0.9.13.1-150200.4.27.1 * librfxencode0-debuginfo-0.9.13.1-150200.4.27.1 * xrdp-debugsource-0.9.13.1-150200.4.27.1 * xrdp-0.9.13.1-150200.4.27.1 * librfxencode0-0.9.13.1-150200.4.27.1 ## References: * https://www.suse.com/security/cve/CVE-2023-42822.html * https://bugzilla.suse.com/show_bug.cgi?id=1215803 . The recent xrdp upgrade on SUSE targets the vulnerabilities identified in CVE-2023-42822; ensure that updates are executed across several affected systems.. xrdp Update,SUSE Security Advisory. . LinuxSecurity.com Team
Release notes for xrdp v0.9.23.1 (2023/09/27) This is a security fix release for CVE-2023-42822. This update is recommended for all xrdp users. Security fixes - CVE-2023-42822: Unchecked access to font glyph info. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-b781647782 2023-11-03 18:20:20.950810 -------------------------------------------------------------------------------- Name : xrdp Product : Fedora 39 Version : 0.9.23.1 Release : 1.fc39 URL : http://www.xrdp.org/ Summary : Open source remote desktop protocol (RDP) server Description : xrdp provides a fully functional RDP server compatible with a wide range of RDP clients, including FreeRDP and Microsoft RDP client. -------------------------------------------------------------------------------- Update Information: Release notes for xrdp v0.9.23.1 (2023/09/27) This is a security fix release for CVE-2023-42822. This update is recommended for all xrdp users. Security fixes - CVE-2023-42822: Unchecked access to font glyph info -------------------------------------------------------------------------------- ChangeLog: * Thu Sep 28 2023 Bojan Smojver - 1:0.9.23.1-1 - Update to 0.9.23.1 - CVE-2023-42822 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2242232 - CVE-2023-42822 xrdp: Unchecked access to font glyph info [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2242232 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-b781647782' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
OpenJDK: Font layout engine out of bounds access setCurrGlyphID() (2D, 8219022) (CVE-2019-2698) * OpenJDK: Slow conversion of BigDecimal to long (Libraries, 8211936) (CVE-2019-2602) * OpenJDK: Incorrect skeleton selection in RMI registry server-side dispatch handling (RMI, 8218453) (CVE-2019-2684) SL6 x86_64 java-1.7.0-openjdk-1.7.0.221-2.6.18.0.el6_10.x86_64.rpm java-1.7.0-openjd [More...]. Synopsis: Important: java-1.7.0-openjdk security update Advisory ID: SLSA-2019:0790-1 Issue Date: 2019-04-22 CVE Numbers: CVE-2019-2602 CVE-2019-2698 CVE-2019-2684 -- Security Fix(es): * OpenJDK: Font layout engine out of bounds access setCurrGlyphID() (2D, 8219022) (CVE-2019-2698) * OpenJDK: Slow conversion of BigDecimal to long (Libraries, 8211936) (CVE-2019-2602) * OpenJDK: Incorrect skeleton selection in RMI registry server-side dispatch handling (RMI, 8218453) (CVE-2019-2684) -- SL6 x86_64 java-1.7.0-openjdk-1.7.0.221-2.6.18.0.el6_10.x86_64.rpm java-1.7.0-openjdk-debuginfo-1.7.0.221-2.6.18.0.el6_10.x86_64.rpm java-1.7.0-openjdk-devel-1.7.0.221-2.6.18.0.el6_10.x86_64.rpm java-1.7.0-openjdk-demo-1.7.0.221-2.6.18.0.el6_10.x86_64.rpm java-1.7.0-openjdk-src-1.7.0.221-2.6.18.0.el6_10.x86_64.rpm i386 java-1.7.0-openjdk-1.7.0.221-2.6.18.0.el6_10.i686.rpm java-1.7.0-openjdk-debuginfo-1.7.0.221-2.6.18.0.el6_10.i686.rpm java-1.7.0-openjdk-devel-1.7.0.221-2.6.18.0.el6_10.i686.rpm java-1.7.0-openjdk-demo-1.7.0.221-2.6.18.0.el6_10.i686.rpm java-1.7.0-openjdk-src-1.7.0.221-2.6.18.0.el6_10.i686.rpm noarch java-1.7.0-openjdk-javadoc-1.7.0.221-2.6.18.0.el6_10.noarch.rpm - Scientific Linux Development Team . Important security patch for java-1.7.0-openjdk resolves numerous vulnerabilities. Update to the newest version today.. Java Security Update, SL6 Java Fix, OpenJDK 1.7.0. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.