Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2022-23613

Опубликовано: 07 фев. 2022
Источник: ubuntu
Приоритет: medium
CVSS2: 7.2
CVSS3: 7.8

Описание

xrdp is an open source remote desktop protocol (RDP) server. In affected versions an integer underflow leading to a heap overflow in the sesman server allows any unauthenticated attacker which is able to locally access a sesman server to execute code as root. This vulnerability has been patched in version 0.9.18.1 and above. Users are advised to upgrade. There are no known workarounds.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

needs-triage

esm-apps/bionic

released

0.9.5-2ubuntu0.1~esm2
esm-apps/focal

released

0.9.12-1ubuntu0.1+esm1
esm-apps/jammy

released

0.9.17-2ubuntu2+esm1
esm-apps/noble

needs-triage

esm-apps/xenial

released

0.6.1-2ubuntu0.3+esm3
esm-infra-legacy/trusty

released

0.6.0-1ubuntu0.1+esm3
focal

ignored

end of standard support, was needed
impish

ignored

end of life

Показывать по

7.2 High

CVSS2

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
nvd
почти 4 года назад

xrdp is an open source remote desktop protocol (RDP) server. In affected versions an integer underflow leading to a heap overflow in the sesman server allows any unauthenticated attacker which is able to locally access a sesman server to execute code as root. This vulnerability has been patched in version 0.9.18.1 and above. Users are advised to upgrade. There are no known workarounds.

CVSS3: 7.8
debian
почти 4 года назад

xrdp is an open source remote desktop protocol (RDP) server. In affect ...

CVSS3: 7.8
fstec
почти 4 года назад

Уязвимость сервера XRDP, связанная с целочисленной потерей значимости, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

7.2 High

CVSS2

7.8 High

CVSS3