PT-2017-14639 · Xrdp+3 · Xrdp+3
Carnil
·
Published
2017-11-23
·
Updated
2024-06-15
·
CVE-2017-16927
CVSS v3.1
8.4
High
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
xrdp versions prior to 0.9.5
Description
The issue is related to the
scp v0s accept function in sesman/libscp/libscp v0.c, which uses an untrusted integer as a write length. This can be exploited by local users to cause a denial of service, resulting in a buffer overflow and application crash, or possibly have other unspecified impacts via a crafted input stream.Recommendations
For xrdp versions prior to 0.9.5, update to version 0.9.5 or later to resolve the issue.
Fix
DoS
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Suse
Ubuntu
Xrdp