Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-42822

Опубликовано: 27 сент. 2023
Источник: nvd
CVSS3: 4.6
CVSS3: 6.5
EPSS Низкий

Описание

xrdp is an open source remote desktop protocol server. Access to the font glyphs in xrdp_painter.c is not bounds-checked . Since some of this data is controllable by the user, this can result in an out-of-bounds read within the xrdp executable. The vulnerability allows an out-of-bounds read within a potentially privileged process. On non-Debian platforms, xrdp tends to run as root. Potentially an out-of-bounds write can follow the out-of-bounds read. There is no denial-of-service impact, providing xrdp is running in forking mode. This issue has been addressed in release 0.9.23.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:neutrinolabs:xrdp:*:*:*:*:*:*:*:*
Версия до 0.9.23.1 (исключая)
Конфигурация 2

Одно из

cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*

EPSS

Процентиль: 54%
0.00311
Низкий

4.6 Medium

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-125
CWE-125

Связанные уязвимости

CVSS3: 4.6
ubuntu
больше 1 года назад

xrdp is an open source remote desktop protocol server. Access to the font glyphs in xrdp_painter.c is not bounds-checked . Since some of this data is controllable by the user, this can result in an out-of-bounds read within the xrdp executable. The vulnerability allows an out-of-bounds read within a potentially privileged process. On non-Debian platforms, xrdp tends to run as root. Potentially an out-of-bounds write can follow the out-of-bounds read. There is no denial-of-service impact, providing xrdp is running in forking mode. This issue has been addressed in release 0.9.23.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 4.6
debian
больше 1 года назад

xrdp is an open source remote desktop protocol server. Access to the f ...

suse-cvrf
больше 1 года назад

Security update for xrdp

CVSS3: 4.6
fstec
больше 1 года назад

Уязвимость компонента xrdp_painter.c сервера XRDP, позволяющая нарушителю получить доступ к защищаемой информации

suse-cvrf
больше 1 года назад

Security update for xrdp

EPSS

Процентиль: 54%
0.00311
Низкий

4.6 Medium

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-125
CWE-125