Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-16927

Опубликовано: 23 нояб. 2017
Источник: nvd
CVSS3: 8.4
CVSS2: 7.2
EPSS Низкий

Описание

The scp_v0s_accept function in sesman/libscp/libscp_v0.c in the session manager in xrdp through 0.9.4 uses an untrusted integer as a write length, which allows local users to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted input stream.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:neutrinolabs:xrdp:*:*:*:*:*:*:*:*
Версия до 0.9.4 (включая)
Конфигурация 2
cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*

EPSS

Процентиль: 32%
0.00124
Низкий

8.4 High

CVSS3

7.2 High

CVSS2

Дефекты

CWE-119

Связанные уязвимости

CVSS3: 8.4
ubuntu
почти 8 лет назад

The scp_v0s_accept function in sesman/libscp/libscp_v0.c in the session manager in xrdp through 0.9.4 uses an untrusted integer as a write length, which allows local users to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted input stream.

CVSS3: 8.4
debian
почти 8 лет назад

The scp_v0s_accept function in sesman/libscp/libscp_v0.c in the sessio ...

CVSS3: 8.4
github
больше 3 лет назад

The scp_v0s_accept function in sesman/libscp/libscp_v0.c in the session manager in xrdp through 0.9.4 uses an untrusted integer as a write length, which allows local users to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted input stream.

suse-cvrf
больше 6 лет назад

Security update for xrdp

suse-cvrf
больше 6 лет назад

Security update for xrdp

EPSS

Процентиль: 32%
0.00124
Низкий

8.4 High

CVSS3

7.2 High

CVSS2

Дефекты

CWE-119