Neutrinolabs

Xrdp

18 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.19%
  • Veröffentlicht 09.12.2022 18:15:14
  • Zuletzt bearbeitet 21.11.2024 06:48:38

xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a Out of Bound Write in xrdp_mm_trans_process_drdynvc_channel_open() function. There are no known...

  • EPSS 0.16%
  • Veröffentlicht 09.12.2022 18:15:13
  • Zuletzt bearbeitet 21.11.2024 06:48:38

xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a buffer over flow in audin_send_open() function. There are no known workarounds for this issue. ...

  • EPSS 0.14%
  • Veröffentlicht 09.12.2022 18:15:13
  • Zuletzt bearbeitet 21.11.2024 06:48:37

xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a buffer over flow in xrdp_login_wnd_create() function. There are no known workarounds for this i...

  • EPSS 0.29%
  • Veröffentlicht 07.02.2022 22:15:08
  • Zuletzt bearbeitet 21.11.2024 06:48:56

xrdp is an open source remote desktop protocol (RDP) server. In affected versions an integer underflow leading to a heap overflow in the sesman server allows any unauthenticated attacker which is able to locally access a sesman server to execute code...

  • EPSS 0.8%
  • Veröffentlicht 30.06.2020 16:15:16
  • Zuletzt bearbeitet 21.11.2024 05:32:12

The xrdp-sesman service before version 0.9.13.1 can be crashed by connecting over port 3350 and supplying a malicious payload. Once the xrdp-sesman process is dead, an unprivileged attacker on the server could then proceed to start their own imposter...

  • EPSS 0.12%
  • Veröffentlicht 23.11.2017 06:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The scp_v0s_accept function in sesman/libscp/libscp_v0.c in the session manager in xrdp through 0.9.4 uses an untrusted integer as a write length, which allows local users to cause a denial of service (buffer overflow and application crash) or possib...

  • EPSS 0.18%
  • Veröffentlicht 17.03.2017 09:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

xrdp 0.9.1 calls the PAM function auth_start_session() in an incorrect location, leading to PAM session modules not being properly initialized, with a potential consequence of incorrect configurations or elevation of privileges, aka a pam_limits.so b...

  • EPSS 0.35%
  • Veröffentlicht 16.12.2016 09:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

An issue was discovered in xrdp before 0.9.1. When successfully logging in using RDP into an xrdp session, the file ~/.vnc/sesman_${username}_passwd is created. Its content is the equivalent of the user's cleartext password, DES encrypted with a know...