oss-sec mailing list archives
CVE request: xrdp
From: Thomas Biege <thomas () suse de>
Date: Mon, 12 Jan 2009 12:08:12 +0100
Hi, this one is a bit older but seems not to have CVE-IDs assigned yet. http://packetstormsecurity.org/0812-advisories/VA_VD_87_08_XRDP.pdf ------------------------------------------------------------------------------- Multiple vulnerabilities in xrdp Discovered by: Hamid Ebadi CSIRT Team Member Amirkabir University CSIRT Laboratory (APA Laboratory) autcert () aut ac ir Introduction Based on the work of rdesktop, xrdp uses the remote desktop protocol to present a GUI to the user. The goal of this project is to provide a fully functional Linux terminal server, capable of accepting connections from rdesktop and Microsoft's own terminal server / remote desktop clients. (http://xrdp.sourceforge.net) There are multiple buffer overflow vulnerabilities in xrdp which could be used by malicious attackers to execute arbitary code on the system. Vulnerable version xrdp <=0.4.1 ... ------------------------------------------------------------------------------- -- Bye, Thomas -- Thomas Biege <thomas () suse de>, SUSE LINUX, Security Support & Auditing SUSE LINUX Products GmbH, GF: Markus Rex, HRB 16746 (AG Nuernberg) -- Hamming's Motto: The purpose of computing is insight, not numbers. -- Richard W. Hamming
Current thread:
- CVE request: xrdp Thomas Biege (Jan 12)
- Re: CVE request: xrdp Steven M. Christey (Jan 20)