Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2020-4044

Опубликовано: 30 июн. 2020
Источник: ubuntu
Приоритет: medium
CVSS2: 4.6
CVSS3: 7.5

Описание

The xrdp-sesman service before version 0.9.13.1 can be crashed by connecting over port 3350 and supplying a malicious payload. Once the xrdp-sesman process is dead, an unprivileged attacker on the server could then proceed to start their own imposter sesman service listening on port 3350. This will allow them to capture any user credentials that are submitted to XRDP and approve or reject arbitrary login credentials. For xorgxrdp sessions in particular, this allows an unauthorized user to hijack an existing session. This is a buffer overflow attack, so there may be a risk of arbitrary code execution as well.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needed
devel

not-affected

0.9.12-1.1
eoan

ignored

end of life
esm-apps/bionic

released

0.9.5-2ubuntu0.1~esm1
esm-apps/focal

released

0.9.12-1ubuntu0.1
esm-apps/jammy

not-affected

0.9.12-1.1
esm-apps/xenial

released

0.6.1-2ubuntu0.3+esm2
esm-infra-legacy/trusty

released

0.6.0-1ubuntu0.1+esm2
focal

released

0.9.12-1ubuntu0.1
groovy

not-affected

0.9.12-1.1

Показывать по

4.6 Medium

CVSS2

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
больше 5 лет назад

The xrdp-sesman service before version 0.9.13.1 can be crashed by connecting over port 3350 and supplying a malicious payload. Once the xrdp-sesman process is dead, an unprivileged attacker on the server could then proceed to start their own imposter sesman service listening on port 3350. This will allow them to capture any user credentials that are submitted to XRDP and approve or reject arbitrary login credentials. For xorgxrdp sessions in particular, this allows an unauthorized user to hijack an existing session. This is a buffer overflow attack, so there may be a risk of arbitrary code execution as well.

CVSS3: 7.5
debian
больше 5 лет назад

The xrdp-sesman service before version 0.9.13.1 can be crashed by conn ...

suse-cvrf
больше 5 лет назад

Security update for xrdp

suse-cvrf
больше 5 лет назад

Security update for xrdp

suse-cvrf
больше 5 лет назад

Security update for xrdp

4.6 Medium

CVSS2

7.5 High

CVSS3