Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-35512

Опубликовано: 17 апр. 2026
Источник: debian

Описание

xrdp is an open source RDP server. Versions through 0.10.5 have a heap-based buffer overflow in the EGFX (graphics dynamic virtual channel) implementation due to insufficient validation of client-controlled size parameters, allowing an out-of-bounds write via crafted PDUs. Pre-authentication exploitation can crash the process, while post-authentication exploitation may achieve remote code execution. This issue has been fixed in version 0.10.6. If users are unable to immediately update, they should run xrdp as a non-privileged user (default since 0.10.2) to limit the impact of successful exploitation.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
xrdpfixed0.10.6-1package
xrdpnot-affectedbookwormpackage
xrdpnot-affectedbullseyepackage

Примечания

  • https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-jg6p-7fg8-9hh6

  • https://github.com/neutrinolabs/xrdp/commit/8c407ce3ed690100fd9fd259c506f526ab74ee5f (v0.10.6)

Связанные уязвимости

CVSS3: 8.8
ubuntu
4 месяца назад

xrdp is an open source RDP server. Versions through 0.10.5 have a heap-based buffer overflow in the EGFX (graphics dynamic virtual channel) implementation due to insufficient validation of client-controlled size parameters, allowing an out-of-bounds write via crafted PDUs. Pre-authentication exploitation can crash the process, while post-authentication exploitation may achieve remote code execution. This issue has been fixed in version 0.10.6. If users are unable to immediately update, they should run xrdp as a non-privileged user (default since 0.10.2) to limit the impact of successful exploitation.

CVSS3: 8.8
nvd
4 месяца назад

xrdp is an open source RDP server. Versions through 0.10.5 have a heap-based buffer overflow in the EGFX (graphics dynamic virtual channel) implementation due to insufficient validation of client-controlled size parameters, allowing an out-of-bounds write via crafted PDUs. Pre-authentication exploitation can crash the process, while post-authentication exploitation may achieve remote code execution. This issue has been fixed in version 0.10.6. If users are unable to immediately update, they should run xrdp as a non-privileged user (default since 0.10.2) to limit the impact of successful exploitation.

CVSS3: 10
fstec
4 месяца назад

Уязвимость сервера XRDP, связанная с переполнением буфера в динамической памяти, позволяющая нарушителю выполнить произвольный код