Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2023-40184

Опубликовано: 30 авг. 2023
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 2.6

Описание

xrdp is an open source remote desktop protocol (RDP) server. In versions prior to 0.9.23 improper handling of session establishment errors allows bypassing OS-level session restrictions. The auth_start_session function can return non-zero (1) value on, e.g., PAM error which may result in in session restrictions such as max concurrent sessions per user by PAM (ex ./etc/security/limits.conf) to be bypassed. Users (administrators) don't use restrictions by PAM are not affected. This issue has been addressed in release version 0.9.23. Users are advised to upgrade. There are no known workarounds for this issue.

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

not-affected

0.9.24-4
esm-apps/bionic

released

0.9.5-2ubuntu0.1~esm2
esm-apps/focal

released

0.9.12-1ubuntu0.1+esm1
esm-apps/jammy

released

0.9.17-2ubuntu2+esm1
esm-apps/noble

needs-triage

esm-apps/xenial

released

0.6.1-2ubuntu0.3+esm3
esm-infra-legacy/trusty

not-affected

0.6.0-1ubuntu0.1+esm3
focal

ignored

end of standard support, was needed
jammy

needed

Показывать по

EPSS

Процентиль: 26%
0.00088
Низкий

2.6 Low

CVSS3

Связанные уязвимости

CVSS3: 2.6
nvd
почти 2 года назад

xrdp is an open source remote desktop protocol (RDP) server. In versions prior to 0.9.23 improper handling of session establishment errors allows bypassing OS-level session restrictions. The `auth_start_session` function can return non-zero (1) value on, e.g., PAM error which may result in in session restrictions such as max concurrent sessions per user by PAM (ex ./etc/security/limits.conf) to be bypassed. Users (administrators) don't use restrictions by PAM are not affected. This issue has been addressed in release version 0.9.23. Users are advised to upgrade. There are no known workarounds for this issue.

CVSS3: 2.6
debian
почти 2 года назад

xrdp is an open source remote desktop protocol (RDP) server. In versio ...

suse-cvrf
больше 1 года назад

Security update for xrdp

suse-cvrf
почти 2 года назад

Security update for xrdp

CVSS3: 6.5
fstec
почти 2 года назад

Уязвимость функции auth_start_session() сервера XRDP, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 26%
0.00088
Низкий

2.6 Low

CVSS3