Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-39917

Опубликовано: 12 июл. 2024
Источник: debian
EPSS Низкий

Описание

xrdp is an open source RDP server. xrdp versions prior to 0.10.0 have a vulnerability that allows attackers to make an infinite number of login attempts. The number of max login attempts is supposed to be limited by a configuration parameter `MaxLoginRetry` in `/etc/xrdp/sesman.ini`. However, this mechanism was not effectively working. As a result, xrdp allows an infinite number of login attempts.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
xrdpfixed0.10.1-1package
xrdpno-dsabookwormpackage

Примечания

  • https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-7w22-h4w7-8j5j

  • https://github.com/neutrinolabs/xrdp/commit/8ac2f6db34649a93d3c9c4fe8fda61203702e615 (devel)

  • https://github.com/neutrinolabs/xrdp/commit/61b509f1d5d9b85128504c7b752e6e36d7b60b15 (v0.10.1)

  • While claimed in GHSA-7w22-h4w7-8j5j that issue is fixed in 0.10.0 the referenced

  • commit is not included in 0.10.0.

EPSS

Процентиль: 57%
0.00353
Низкий

Связанные уязвимости

CVSS3: 7.2
ubuntu
12 месяцев назад

xrdp is an open source RDP server. xrdp versions prior to 0.10.0 have a vulnerability that allows attackers to make an infinite number of login attempts. The number of max login attempts is supposed to be limited by a configuration parameter `MaxLoginRetry` in `/etc/xrdp/sesman.ini`. However, this mechanism was not effectively working. As a result, xrdp allows an infinite number of login attempts.

CVSS3: 7.2
nvd
12 месяцев назад

xrdp is an open source RDP server. xrdp versions prior to 0.10.0 have a vulnerability that allows attackers to make an infinite number of login attempts. The number of max login attempts is supposed to be limited by a configuration parameter `MaxLoginRetry` in `/etc/xrdp/sesman.ini`. However, this mechanism was not effectively working. As a result, xrdp allows an infinite number of login attempts.

suse-cvrf
5 месяцев назад

Security update for xrdp

suse-cvrf
5 месяцев назад

Security update for xrdp

suse-cvrf
5 месяцев назад

Security update for xrdp

EPSS

Процентиль: 57%
0.00353
Низкий