Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2017-16927

Опубликовано: 23 нояб. 2017
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 7.2
CVSS3: 8.4

Описание

The scp_v0s_accept function in sesman/libscp/libscp_v0.c in the session manager in xrdp through 0.9.4 uses an untrusted integer as a write length, which allows local users to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted input stream.

РелизСтатусПримечание
artful

ignored

end of life
bionic

not-affected

0.9.5-2
cosmic

not-affected

0.9.5-2
devel

not-affected

0.9.5-2
disco

not-affected

0.9.5-2
eoan

not-affected

0.9.5-2
esm-apps/bionic

not-affected

0.9.5-2
esm-apps/focal

not-affected

0.9.5-2
esm-apps/jammy

not-affected

0.9.5-2
esm-apps/xenial

released

0.6.1-2ubuntu0.3+esm1

Показывать по

EPSS

Процентиль: 32%
0.00124
Низкий

7.2 High

CVSS2

8.4 High

CVSS3

Связанные уязвимости

CVSS3: 8.4
nvd
почти 8 лет назад

The scp_v0s_accept function in sesman/libscp/libscp_v0.c in the session manager in xrdp through 0.9.4 uses an untrusted integer as a write length, which allows local users to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted input stream.

CVSS3: 8.4
debian
почти 8 лет назад

The scp_v0s_accept function in sesman/libscp/libscp_v0.c in the sessio ...

CVSS3: 8.4
github
больше 3 лет назад

The scp_v0s_accept function in sesman/libscp/libscp_v0.c in the session manager in xrdp through 0.9.4 uses an untrusted integer as a write length, which allows local users to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted input stream.

suse-cvrf
больше 6 лет назад

Security update for xrdp

suse-cvrf
больше 6 лет назад

Security update for xrdp

EPSS

Процентиль: 32%
0.00124
Низкий

7.2 High

CVSS2

8.4 High

CVSS3