Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2023-42822

Опубликовано: 27 сент. 2023
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 4.6

Описание

xrdp is an open source remote desktop protocol server. Access to the font glyphs in xrdp_painter.c is not bounds-checked . Since some of this data is controllable by the user, this can result in an out-of-bounds read within the xrdp executable. The vulnerability allows an out-of-bounds read within a potentially privileged process. On non-Debian platforms, xrdp tends to run as root. Potentially an out-of-bounds write can follow the out-of-bounds read. There is no denial-of-service impact, providing xrdp is running in forking mode. This issue has been addressed in release 0.9.23.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

not-affected

0.9.24-4
esm-apps/bionic

released

0.9.5-2ubuntu0.1~esm2
esm-apps/focal

released

0.9.12-1ubuntu0.1+esm1
esm-apps/jammy

released

0.9.17-2ubuntu2+esm1
esm-apps/noble

needs-triage

esm-apps/xenial

released

0.6.1-2ubuntu0.3+esm3
esm-infra-legacy/trusty

not-affected

0.6.0-1ubuntu0.1+esm3
focal

ignored

end of standard support, was needed
jammy

needed

Показывать по

EPSS

Процентиль: 54%
0.00311
Низкий

4.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.6
nvd
больше 1 года назад

xrdp is an open source remote desktop protocol server. Access to the font glyphs in xrdp_painter.c is not bounds-checked . Since some of this data is controllable by the user, this can result in an out-of-bounds read within the xrdp executable. The vulnerability allows an out-of-bounds read within a potentially privileged process. On non-Debian platforms, xrdp tends to run as root. Potentially an out-of-bounds write can follow the out-of-bounds read. There is no denial-of-service impact, providing xrdp is running in forking mode. This issue has been addressed in release 0.9.23.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 4.6
debian
больше 1 года назад

xrdp is an open source remote desktop protocol server. Access to the f ...

suse-cvrf
больше 1 года назад

Security update for xrdp

CVSS3: 4.6
fstec
больше 1 года назад

Уязвимость компонента xrdp_painter.c сервера XRDP, позволяющая нарушителю получить доступ к защищаемой информации

suse-cvrf
больше 1 года назад

Security update for xrdp

EPSS

Процентиль: 54%
0.00311
Низкий

4.6 Medium

CVSS3