Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
An update that fixes 19 vulnerabilities is now available.. openSUSE Security Update: Security update for rdesktop ______________________________________________________________________________ Announcement ID: openSUSE-SU-2019:2135-1 Rating: important References: #1121448 Cross-References: CVE-2018-20174 CVE-2018-20175 CVE-2018-20176 CVE-2018-20177 CVE-2018-20178 CVE-2018-20179 CVE-2018-20180 CVE-2018-20181 CVE-2018-20182 CVE-2018-8791 CVE-2018-8792 CVE-2018-8793 CVE-2018-8794 CVE-2018-8795 CVE-2018-8796 CVE-2018-8797 CVE-2018-8798 CVE-2018-8799 CVE-2018-8800 Affected Products: openSUSE Leap 15.1 openSUSE Backports SLE-15-SP1 ______________________________________________________________________________ An update that fixes 19 vulnerabilities is now available. Description: This update for rdesktop fixes the following issues: rdesktop was updated to 1.8.6: * Fix protocol code handling new licenses rdesktop was updated to 1.8.5: * Add bounds checking to protocol handling in order to fix many security problems when communicating with a malicious server. rdesktop was updated to 1.8.4 (fix for boo#1121448): * Add rdp_protocol_error function that is used in several fixes * Refactor of process_bitmap_updates * Fix possible integer overflow in s_check_rem() on 32bit arch * Fix memory corruption in process_bitmap_data - CVE-2018-8794 * Fix remote code execution in process_bitmap_data - CVE-2018-8795 * Fix remote code execution in process_plane - CVE-2018-8797 * Fix Denial of Service in mcs_recv_connect_response - CVE-2018-20175 * Fix Denial of Service in mcs_parse_domain_params - CVE-2018-20175 * Fix Denial of Service in sec_parse_crypt_info - CVE-2018-20176 * Fix Denial of Service in sec_recv - CVE-2018-20176 * Fix minor information leak in rdpdr_process -CVE-2018-8791 * Fix Denial of Service in cssp_read_tsrequest - CVE-2018-8792 * Fix remote code execution in cssp_read_tsrequest - CVE-2018-8793 * Fix Denial of Service in process_bitmap_data - CVE-2018-8796 * Fix minor information leak in rdpsnd_process_ping - CVE-2018-8798 * Fix Denial of Service in process_secondary_order - CVE-2018-8799 * Fix remote code execution in in ui_clip_handle_data - CVE-2018-8800 * Fix major information leak in ui_clip_handle_data - CVE-2018-20174 * Fix memory corruption in rdp_in_unistr - CVE-2018-20177 * Fix Denial of Service in process_demand_active - CVE-2018-20178 * Fix remote code execution in lspci_process - CVE-2018-20179 * Fix remote code execution in rdpsnddbg_process - CVE-2018-20180 * Fix remote code execution in seamless_process - CVE-2018-20181 * Fix remote code execution in seamless_process_line - CVE-2018-20182 * Fix building against OpenSSL 1.1 - remove obsolete patches * rdesktop-Fix-OpenSSL-1.1-compability-issues.patch * rdesktop-Fix-crash-in-rdssl_cert_to_rkey.patch - update changes file * add missing info about bugzilla 1121448 - Added rdesktop-Fix-decryption.patch Patch from https://github.com/rdesktop/rdesktop/pull/334 to fix connections to VirtualBox. - update to 1.8.6 * Fix protocol code handling new licenses - update to 1.8.5 * Add bounds checking to protocol handling in order to fix many security problems when communicating with a malicious server. - Trim redundant wording from description. - Use %make_install. - update to 1.8.4 (fix for boo#1121448) * Add rdp_protocol_error function that is used in several fixes * Refactor of process_bitmap_updates * Fix possible integer overflow in s_check_rem() on 32bit arch * Fix memory corruption in process_bitmap_data - CVE-2018-8794 * Fix remote code execution in process_bitmap_data - CVE-2018-8795 * Fix remote code execution in process_plane - CVE-2018-8797 * Fix Denial of Service inmcs_recv_connect_response - CVE-2018-20175 * Fix Denial of Service in mcs_parse_domain_params - CVE-2018-20175 * Fix Denial of Service in sec_parse_crypt_info - CVE-2018-20176 * Fix Denial of Service in sec_recv - CVE-2018-20176 * Fix minor information leak in rdpdr_process - CVE-2018-8791 * Fix Denial of Service in cssp_read_tsrequest - CVE-2018-8792 * Fix remote code execution in cssp_read_tsrequest - CVE-2018-8793 * Fix Denial of Service in process_bitmap_data - CVE-2018-8796 * Fix minor information leak in rdpsnd_process_ping - CVE-2018-8798 * Fix Denial of Service in process_secondary_order - CVE-2018-8799 * Fix remote code execution in in ui_clip_handle_data - CVE-2018-8800 * Fix major information leak in ui_clip_handle_data - CVE-2018-20174 * Fix memory corruption in rdp_in_unistr - CVE-2018-20177 * Fix Denial of Service in process_demand_active - CVE-2018-20178 * Fix remote code execution in lspci_process - CVE-2018-20179 * Fix remote code execution in rdpsnddbg_process - CVE-2018-20180 * Fix remote code execution in seamless_process - CVE-2018-20181 * Fix remote code execution in seamless_process_line - CVE-2018-20182 * Fix building against OpenSSL 1.1 Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.1: zypper in -t patch openSUSE-2019-2135=1 - openSUSE Backports SLE-15-SP1: zypper in -t patch openSUSE-2019-2135=1 Package List: - openSUSE Leap 15.1 (x86_64): rdesktop-1.8.6-lp151.2.3.1 rdesktop-debuginfo-1.8.6-lp151.2.3.1 rdesktop-debugsource-1.8.6-lp151.2.3.1 - openSUSE Backports SLE-15-SP1 (aarch64 ppc64le s390x x86_64): rdesktop-1.8.6-bp151.2.3.1 References: https://www.suse.com/security/cve/CVE-2018-20174.html https://www.suse.com/security/cve/CVE-2018-20175.html https://www.suse.com/security/cve/CVE-2018-20176.html https://www.suse.com/security/cve/CVE-2018-20177.html https://www.suse.com/security/cve/CVE-2018-20178.html https://www.suse.com/security/cve/CVE-2018-20179.html https://www.suse.com/security/cve/CVE-2018-20180.html https://www.suse.com/security/cve/CVE-2018-20181.html https://www.suse.com/security/cve/CVE-2018-20182.html https://www.suse.com/security/cve/CVE-2018-8791.html https://www.suse.com/security/cve/CVE-2018-8792.html https://www.suse.com/security/cve/CVE-2018-8793.html https://www.suse.com/security/cve/CVE-2018-8794.html https://www.suse.com/security/cve/CVE-2018-8795.html https://www.suse.com/security/cve/CVE-2018-8796.html https://www.suse.com/security/cve/CVE-2018-8797.html https://www.suse.com/security/cve/CVE-2018-8798.html https://www.suse.com/security/cve/CVE-2018-8799.html https://www.suse.com/security/cve/CVE-2018-8800.html https://bugzilla.suse.com/1121448 -- . Essential patch for rdesktop on openSUSE addresses 19 security flaws, highlighting serious remote execution threats.. openSUSE,rdesktop,security update,Denial of Service,remote code execution. . Severity: Important. LinuxSecurity.com Team
Multiple security issues were found in the rdesktop RDP client, which could result in denial of service and the execution of arbitrary code. References: - https://bugs.mageia.org/show_bug.cgi?id=25274 . MGASA-2019-0247 - Updated rdesktop packages fix security vulnerabilities Publication date: 06 Sep 2019 URL: https://advisories.mageia.org/MGASA-2019-0247.html Type: security Affected Mageia releases: 6, 7 Multiple security issues were found in the rdesktop RDP client, which could result in denial of service and the execution of arbitrary code. References: - https://bugs.mageia.org/show_bug.cgi?id=25274 SRPMS: - 7/core/rdesktop-1.8.6-1.mga7 - 6/core/rdesktop-1.8.6-1.mga6 . Significant vulnerabilities in rdesktop RDP client patched in Mageia's update, crucial exploitation threats mitigated.. Mageia Security Advisory, Rdesktop Update, Denial of Service Fix. . Severity: Important. LinuxSecurity.com Team
Update to 1.8.6 release which fixes a bug in 1.8.5. 1.8.5 is a security release to address various buffer overflow and overrun issues in the rdesktop protocol handling.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-a457303ffc 2019-09-06 12:57:51.121029 --------------------------------------------------------------------------------Name : rdesktop Product : Fedora 29 Version : 1.8.6 Release : 1.fc29 URL : http://www.rdesktop.org/ Summary : X client for remote desktop into Windows Terminal Server Description : rdesktop is an open source client for Windows NT Terminal Server and Windows 2000 & 2003 Terminal Services, capable of natively speaking Remote Desktop Protocol (RDP) in order to present the user's NT desktop. Unlike Citrix ICA, no server extensions are required. --------------------------------------------------------------------------------Update Information: Update to 1.8.6 release which fixes a bug in 1.8.5. 1.8.5 is a security release to address various buffer overflow and overrun issues in the rdesktop protocol handling. --------------------------------------------------------------------------------ChangeLog: * Fri Aug 16 2019 Charles R. Anderson - 1.8.6-1 - Update to 1.8.6 release which fixes a bug in 1.8.5. - 1.8.5 is a security release to address various buffer overflow and overrun issues in the rdesktop protocol handling. * Fri Jul 26 2019 Fedora Release Engineering - 1.8.4-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild * Sat Feb 2 2019 Fedora Release Engineering - 1.8.4-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild * Tue Jan 29 2019 Charles R. Anderson - 1.8.4-2 - Escape macros in comments - 1.8.4 release security fixes rhbz#1670427: CVE-2018-8794 CVE-2018-8795 CVE-2018-8797 CVE-2018-20175 CVE-2018-20176 CVE-2018-8791 CVE-2018-8792 CVE-2018-8793 CVE-2018-8796 CVE-2018-8798 CVE-2018-8799CVE-2018-8800 CVE-2018-20174 CVE-2018-20177 CVE-2018-20178 CVE-2018-20179 CVE-2018-20180 CVE-2018-20181 CVE-2018-20182 * Sat Jan 26 2019 Charles R. Anderson - 1.8.4-1 - Update to 1.8.4 release * Fri Nov 30 2018 Charles R. Anderson - 1.8.4-0.1 - Update to git master * Sat Jul 14 2018 Fedora Release Engineering - 1.8.3-8 - Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild * Fri Feb 9 2018 Fedora Release Engineering - 1.8.3-7 - Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-a457303ffc' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Update to 1.8.6 release which fixes a bug in 1.8.5. 1.8.5 is a security release to address various buffer overflow and overrun issues in the rdesktop protocol handling.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-baff775841 2019-09-06 12:30:29.164027 --------------------------------------------------------------------------------Name : rdesktop Product : Fedora 30 Version : 1.8.6 Release : 1.fc30 URL : http://www.rdesktop.org/ Summary : X client for remote desktop into Windows Terminal Server Description : rdesktop is an open source client for Windows NT Terminal Server and Windows 2000 & 2003 Terminal Services, capable of natively speaking Remote Desktop Protocol (RDP) in order to present the user's NT desktop. Unlike Citrix ICA, no server extensions are required. --------------------------------------------------------------------------------Update Information: Update to 1.8.6 release which fixes a bug in 1.8.5. 1.8.5 is a security release to address various buffer overflow and overrun issues in the rdesktop protocol handling. --------------------------------------------------------------------------------ChangeLog: * Fri Aug 16 2019 Charles R. Anderson - 1.8.6-1 - Update to 1.8.6 release which fixes a bug in 1.8.5. - 1.8.5 is a security release to address various buffer overflow and overrun issues in the rdesktop protocol handling. * Fri Jul 26 2019 Fedora Release Engineering - 1.8.4-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-baff775841' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details onthe GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
This is a security release to address various buffer overflow and overrun issues in the rdesktop protocol handling identified by Kaspersky Lab and National Cyber Security Centre. rdesktop will now detect any attempts to access invalid areas and refuse . MGASA-2019-0209 - Updated rdesktop packages fix security issues Publication date: 21 Jul 2019 URL: https://advisories.mageia.org/MGASA-2019-0209.html Type: security Affected Mageia releases: 6 This is a security release to address various buffer overflow and overrun issues in the rdesktop protocol handling identified by Kaspersky Lab and National Cyber Security Centre. rdesktop will now detect any attempts to access invalid areas and refuse to continue. References: - https://bugs.mageia.org/show_bug.cgi?id=24797 - https://github.com/rdesktop/rdesktop/releases/tag/v1.8.5 SRPMS: - 6/core/rdesktop-1.8.5-1.mga6 . The update MGASA-2021-0412 from Mageia tackles critical vulnerabilities in gedit, improving protection against unauthorized data manipulations.. rdesktop Security Update,Mageia Security Advisory,Buffer Overflow Fix,rdesktop Protocol Issues,Mageia Releases. . LinuxSecurity.com Team
The update for rdesktop released as 1.8.6-0+deb8u1 introduced a regression which broke RDP protocol negotiation. Updated rdesktop packages are now available to correct this issue. . Package : rdesktop Version : 1.8.6-0+deb8u2 Debian Bug : 930511 The update for rdesktop released as 1.8.6-0+deb8u1 introduced a regression which broke RDP protocol negotiation. Updated rdesktop packages are now available to correct this issue. For Debian 8 "Jessie", this problem has been fixed in version 1.8.6-0+deb8u2. We recommend that you upgrade your rdesktop packages. For the detailed security status of rdesktop please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/rdesktop Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS - -- Jonas Meurer . The recent rdesktop revision addresses a flaw in RDP protocol coordination on Debian. Please update to version 1.8.6-0+deb8u2 immediately.. rdesktop update, Debian security, regression fix, protocol issue, Jessie updates. . Severity: Critical. LinuxSecurity.com Team
Multiple security issues were found in the rdesktop RDP client, which could result in denial of service and the execution of arbitrary code. For the stable distribution (stretch), this problem has been fixed in . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4473-1
Several security vulnerabilities were discovered in the rdesktop RDP client, which could result in buffer overflows and execution of arbitrary code. . Package : rdesktop Version : 1.8.6-0+deb8u1 Debian Bug : 930387 Several security vulnerabilities were discovered in the rdesktop RDP client, which could result in buffer overflows and execution of arbitrary code. For Debian 8 "Jessie", this problem has been fixed in version 1.8.6-0+deb8u1. We recommend that you upgrade your rdesktop packages. For the detailed security status of rdesktop please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/rdesktop Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS - -- Jonas Meurer . Enhance rdesktop to address numerous security vulnerabilities, including potential buffer overflow issues and the risk of arbitrary code execution within Debian 8.. rdesktop security update, Debian LTS, buffer overflow fix, security vulnerabilities. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.