CVE-2022-23613Integer Underflow (Wrap or Wraparound) in Xrdp

Severity
7.8HIGHNVD
EPSS
0.4%
top 40.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 7
Latest updateNov 8

Description

xrdp is an open source remote desktop protocol (RDP) server. In affected versions an integer underflow leading to a heap overflow in the sesman server allows any unauthenticated attacker which is able to locally access a sesman server to execute code as root. This vulnerability has been patched in version 0.9.18.1 and above. Users are advised to upgrade. There are no known workarounds.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages3 packages

Debianneutrinolabs/xrdp< 0.9.17-2.1+2
CVEListV5neutrinolabs/xrdp>= 0.9.17, < 0.9.18.1
NVDneutrinolabs/xrdp0.9.17, 0.9.18+1

Also affects: Fedora 34, 35

Patches

🔴Vulnerability Details

2
CVEList
Privilege escalation on xrdp2022-02-07
OSV
CVE-2022-23613: xrdp is an open source remote desktop protocol (RDP) server2022-02-07

📋Vendor Advisories

2
Ubuntu
xrdp vulnerabilities2023-11-08
Debian
CVE-2022-23613: xrdp - xrdp is an open source remote desktop protocol (RDP) server. In affected version...2022
CVE-2022-23613 — Integer Underflow (Wrap or Wraparound) | cvebase