Debian Xrdp vulnerabilities
22 known vulnerabilities affecting debian/xrdp.
Total CVEs
22
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH10MEDIUM2LOW1
Vulnerabilities
Page 2 of 2
CVE-2023-40184P3LOWCVSS 2.6fixed in xrdp 0.9.21.1-1+deb12u1 (bookworm)2023
CVE-2023-40184 [LOW] CVE-2023-40184: xrdp - xrdp is an open source remote desktop protocol (RDP) server. In versions prior t...
xrdp is an open source remote desktop protocol (RDP) server. In versions prior to 0.9.23 improper handling of session establishment errors allows bypassing OS-level session restrictions. The `auth_start_session` function can return non-zero (1) value on, e.g., PAM error which may result in in session restrictions such as max concurrent sessions per user by PAM (ex ./etc
debian
CVE-2017-16927P4HIGHCVSS 8.4fixed in xrdp 0.9.4-3 (bookworm)2017
CVE-2017-16927 [HIGH] CVE-2017-16927: xrdp - The scp_v0s_accept function in sesman/libscp/libscp_v0.c in the session manager ...
The scp_v0s_accept function in sesman/libscp/libscp_v0.c in the session manager in xrdp through 0.9.4 uses an untrusted integer as a write length, which allows local users to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted input stream.
Scope: local
bookworm: resolved (fixed in 0.9.4-3)
bullseye:
debian
← Previous2 / 2