cbcvebase.

Debian Xrdp vulnerabilities

22 known vulnerabilities affecting debian/xrdp.

Total CVEs
22
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH10MEDIUM2LOW1

Vulnerabilities

Page 1 of 2
CVE-2008-5904P3HIGHCVSS 7.5PoCfixed in xrdp 0.4.0~dfsg-9 (bookworm)2008
CVE-2008-5904 [HIGH] CVE-2008-5904: xrdp - The rdp_rdp_process_color_pointer_pdu function in rdp/rdp_rdp.c in xrdp 0.4.1 an... The rdp_rdp_process_color_pointer_pdu function in rdp/rdp_rdp.c in xrdp 0.4.1 and earlier allows remote RDP servers to have an unknown impact via input data that sets crafted values for certain length variables, leading to a buffer overflow. Scope: local bookworm: resolved (fixed in 0.4.0~dfsg-9) bullseye: resolved (fixed in 0.4.0~dfsg-9) forky: resolved (fixed in 0.4.0~
debian
CVE-2025-68670P2CRITICALCVSS 9.1fixed in xrdp 0.9.21.1-1+deb12u2 (bookworm)2025
CVE-2025-68670 [CRITICAL] CVE-2025-68670: xrdp - xrdp is an open source RDP server. xrdp before v0.10.5 contains an unauthenticat... xrdp is an open source RDP server. xrdp before v0.10.5 contains an unauthenticated stack-based buffer overflow vulnerability. The issue stems from improper bounds checking when processing user domain information during the connection sequence. If exploited, the vulnerability could allow remote attackers to execute arbitrary code on the target system. The vulnerabil
debian
CVE-2024-39917P3HIGHCVSS 7.2fixed in xrdp 0.9.21.1-1+deb12u1 (bookworm)2024
CVE-2024-39917 [HIGH] CVE-2024-39917: xrdp - xrdp is an open source RDP server. xrdp versions prior to 0.10.0 have a vulnerab... xrdp is an open source RDP server. xrdp versions prior to 0.10.0 have a vulnerability that allows attackers to make an infinite number of login attempts. The number of max login attempts is supposed to be limited by a configuration parameter `MaxLoginRetry` in `/etc/xrdp/sesman.ini`. However, this mechanism was not effectively working. As a result, xrdp allows an infin
debian
CVE-2022-23479P3CRITICALCVSS 9.1fixed in xrdp 0.9.21.1-1 (bookworm)2022
CVE-2022-23479 [CRITICAL] CVE-2022-23479: xrdp - xrdp is an open source project which provides a graphical login to remote machin... xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a buffer over flow in xrdp_mm_chan_data_in() function. There are no known workarounds for this issue. Users are advised to upgrade. Scope: local bookworm: resolved (fixed in 0.9.21.1-1) bullseye: resolved (fixed in
debian
CVE-2022-23480P3CRITICALCVSS 9.1fixed in xrdp 0.9.21.1-1 (bookworm)2022
CVE-2022-23480 [CRITICAL] CVE-2022-23480: xrdp - xrdp is an open source project which provides a graphical login to remote machin... xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a buffer over flow in devredir_proc_client_devlist_announce_req() function. There are no known workarounds for this issue. Users are advised to upgrade. Scope: local bookworm: resolved (fixed in 0.9.21.1-1) bullsey
debian
CVE-2022-23477P3CRITICALCVSS 9.1fixed in xrdp 0.9.21.1-1 (bookworm)2022
CVE-2022-23477 [CRITICAL] CVE-2022-23477: xrdp - xrdp is an open source project which provides a graphical login to remote machin... xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a buffer over flow in audin_send_open() function. There are no known workarounds for this issue. Users are advised to upgrade. Scope: local bookworm: resolved (fixed in 0.9.21.1-1) bullseye: resolved (fixed in 0.9.
debian
CVE-2022-23478P3CRITICALCVSS 9.1fixed in xrdp 0.9.21.1-1 (bookworm)2022
CVE-2022-23478 [CRITICAL] CVE-2022-23478: xrdp - xrdp is an open source project which provides a graphical login to remote machin... xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a Out of Bound Write in xrdp_mm_trans_process_drdynvc_channel_open() function. There are no known workarounds for this issue. Users are advised to upgrade. Scope: local bookworm: resolved (fixed in 0.9.21.1-1) bull
debian
CVE-2022-23493P3CRITICALCVSS 9.1fixed in xrdp 0.9.21.1-1 (bookworm)2022
CVE-2022-23493 [CRITICAL] CVE-2022-23493: xrdp - xrdp is an open source project which provides a graphical login to remote machin... xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a Out of Bound Read in xrdp_mm_trans_process_drdynvc_channel_close() function. There are no known workarounds for this issue. Users are advised to upgrade. Scope: local bookworm: resolved (fixed in 0.9.21.1-1) bull
debian
CVE-2022-23468P3MEDIUMCVSS 6.5fixed in xrdp 0.9.21.1-1 (bookworm)2022
CVE-2022-23468 [MEDIUM] CVE-2022-23468: xrdp - xrdp is an open source project which provides a graphical login to remote machin... xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a buffer over flow in xrdp_login_wnd_create() function. There are no known workarounds for this issue. Users are advised to upgrade. Scope: local bookworm: resolved (fixed in 0.9.21.1-1) bullseye: resolved (fixed in
debian
CVE-2022-23483P3HIGHCVSS 7.5fixed in xrdp 0.9.21.1-1 (bookworm)2022
CVE-2022-23483 [HIGH] CVE-2022-23483: xrdp - xrdp is an open source project which provides a graphical login to remote machin... xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a Out of Bound Read in libxrdp_send_to_channel() function. There are no known workarounds for this issue. Users are advised to upgrade. Scope: local bookworm: resolved (fixed in 0.9.21.1-1) bullseye: resolved (fixed in
debian
CVE-2022-23482P3UNKNOWNCVSS 9.1fixed in xrdp 0.9.21.1-1 (bookworm)2022
CVE-2022-23482 [NONE] CVE-2022-23482: xrdp - xrdp is an open source project which provides a graphical login to remote machin... xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a Out of Bound Read in xrdp_sec_process_mcs_data_CS_CORE() function. There are no known workarounds for this issue. Users are advised to upgrade. Scope: local bookworm: resolved (fixed in 0.9.21.1-1) bullseye: resolved
debian
CVE-2022-23481P3UNKNOWNCVSS 9.1fixed in xrdp 0.9.21.1-1 (bookworm)2022
CVE-2022-23481 [NONE] CVE-2022-23481: xrdp - xrdp is an open source project which provides a graphical login to remote machin... xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a Out of Bound Read in xrdp_caps_process_confirm_active() function. There are no known workarounds for this issue. Users are advised to upgrade. Scope: local bookworm: resolved (fixed in 0.9.21.1-1) bullseye: resolved
debian
CVE-2022-23484P3HIGHCVSS 8.2fixed in xrdp 0.9.21.1-1 (bookworm)2022
CVE-2022-23484 [HIGH] CVE-2022-23484: xrdp - xrdp is an open source project which provides a graphical login to remote machin... xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a Integer Overflow in xrdp_mm_process_rail_update_window_text() function. There are no known workarounds for this issue. Users are advised to upgrade. Scope: local bookworm: resolved (fixed in 0.9.21.1-1) bullseye: res
debian
CVE-2020-4044P3HIGHCVSS 7.5fixed in xrdp 0.9.12-1.1 (bookworm)2020
CVE-2020-4044 [HIGH] CVE-2020-4044: xrdp - The xrdp-sesman service before version 0.9.13.1 can be crashed by connecting ove... The xrdp-sesman service before version 0.9.13.1 can be crashed by connecting over port 3350 and supplying a malicious payload. Once the xrdp-sesman process is dead, an unprivileged attacker on the server could then proceed to start their own imposter sesman service listening on port 3350. This will allow them to capture any user credentials that are submitted to XRDP and
debian
CVE-2013-1430P3CRITICALCVSS 9.8fixed in xrdp 0.9.1~2016121126+git5171fa7-1 (bookworm)2013
CVE-2013-1430 [CRITICAL] CVE-2013-1430: xrdp - An issue was discovered in xrdp before 0.9.1. When successfully logging in using... An issue was discovered in xrdp before 0.9.1. When successfully logging in using RDP into an xrdp session, the file ~/.vnc/sesman_${username}_passwd is created. Its content is the equivalent of the user's cleartext password, DES encrypted with a known key. Scope: local bookworm: resolved (fixed in 0.9.1~2016121126+git5171fa7-1) bullseye: resolved (fixed in 0.9.1~2016
debian
CVE-2022-23613P3HIGHCVSS 7.8fixed in xrdp 0.9.17-2.1 (bookworm)2022
CVE-2022-23613 [HIGH] CVE-2022-23613: xrdp - xrdp is an open source remote desktop protocol (RDP) server. In affected version... xrdp is an open source remote desktop protocol (RDP) server. In affected versions an integer underflow leading to a heap overflow in the sesman server allows any unauthenticated attacker which is able to locally access a sesman server to execute code as root. This vulnerability has been patched in version 0.9.18.1 and above. Users are advised to upgrade. There are no k
debian
CVE-2008-5902P3HIGHCVSS 7.5fixed in xrdp 0.4.0~dfsg-9 (bookworm)2008
CVE-2008-5902 [HIGH] CVE-2008-5902: xrdp - Buffer overflow in the xrdp_bitmap_invalidate function in xrdp/xrdp_bitmap.c in ... Buffer overflow in the xrdp_bitmap_invalidate function in xrdp/xrdp_bitmap.c in xrdp 0.4.1 and earlier allows remote attackers to execute arbitrary code via a crafted request. Scope: local bookworm: resolved (fixed in 0.4.0~dfsg-9) bullseye: resolved (fixed in 0.4.0~dfsg-9) forky: resolved (fixed in 0.4.0~dfsg-9) sid: resolved (fixed in 0.4.0~dfsg-9) trixie: resolved (fi
debian
CVE-2008-5903P3HIGHCVSS 7.5fixed in xrdp 0.4.0~dfsg-9 (bookworm)2008
CVE-2008-5903 [HIGH] CVE-2008-5903: xrdp - Array index error in the xrdp_bitmap_def_proc function in xrdp/funcs.c in xrdp 0... Array index error in the xrdp_bitmap_def_proc function in xrdp/funcs.c in xrdp 0.4.1 and earlier allows remote attackers to execute arbitrary code via vectors that manipulate the value of the edit_pos structure member. Scope: local bookworm: resolved (fixed in 0.4.0~dfsg-9) bullseye: resolved (fixed in 0.4.0~dfsg-9) forky: resolved (fixed in 0.4.0~dfsg-9) sid: resolved (
debian
CVE-2023-42822P3MEDIUMCVSS 4.6fixed in xrdp 0.9.21.1-1+deb12u1 (bookworm)2023
CVE-2023-42822 [MEDIUM] CVE-2023-42822: xrdp - xrdp is an open source remote desktop protocol server. Access to the font glyphs... xrdp is an open source remote desktop protocol server. Access to the font glyphs in xrdp_painter.c is not bounds-checked . Since some of this data is controllable by the user, this can result in an out-of-bounds read within the xrdp executable. The vulnerability allows an out-of-bounds read within a potentially privileged process. On non-Debian platforms, xrdp tends
debian
CVE-2017-6967P4HIGHCVSS 7.3fixed in xrdp 0.9.1-9 (bookworm)2017
CVE-2017-6967 [HIGH] CVE-2017-6967: xrdp - xrdp 0.9.1 calls the PAM function auth_start_session() in an incorrect location,... xrdp 0.9.1 calls the PAM function auth_start_session() in an incorrect location, leading to PAM session modules not being properly initialized, with a potential consequence of incorrect configurations or elevation of privileges, aka a pam_limits.so bypass. Scope: local bookworm: resolved (fixed in 0.9.1-9) bullseye: resolved (fixed in 0.9.1-9) forky: resolved (fixed in 0
debian
Debian Xrdp vulnerabilities | cvebase