CVE-2017-6967Improper Authentication in Xrdp

Severity
7.3HIGHNVD
OSV8.4
EPSS
0.2%
top 60.03%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 17
Latest updateMay 13

Description

xrdp 0.9.1 calls the PAM function auth_start_session() in an incorrect location, leading to PAM session modules not being properly initialized, with a potential consequence of incorrect configurations or elevation of privileges, aka a pam_limits.so bypass.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:LExploitability: 3.9 | Impact: 3.4

Affected Packages3 packages

Debianneutrinolabs/xrdp< 0.9.1-9+3
Ubuntuneutrinolabs/xrdp< 0.6.0-1ubuntu0.1+esm1+1

🔴Vulnerability Details

4
GHSA
GHSA-3fgq-wvwm-xq86: xrdp 02022-05-13
OSV
xrdp vulnerabilities2021-03-15
CVEList
CVE-2017-6967: xrdp 02017-03-17
OSV
CVE-2017-6967: xrdp 02017-03-17

📋Vendor Advisories

2
Ubuntu
xrdp vulnerabilities2021-03-15
Debian
CVE-2017-6967: xrdp - xrdp 0.9.1 calls the PAM function auth_start_session() in an incorrect location,...2017

💬Community

3
Bugzilla
CVE-2017-6967 xrdp: Incorrect placement of auth_start_session() [fedora-all]2017-03-20
Bugzilla
CVE-2017-6967 xrdp: Incorrect placement of auth_start_session() [epel-all]2017-03-20
Bugzilla
CVE-2017-6967 xrdp: Incorrect placement of auth_start_session()2017-03-20
CVE-2017-6967 — Improper Authentication in Xrdp | cvebase