PT-2020-6234 · Xrdp+4 · Xrdp-Sesman+4

Ashley Newson

·

Published

2020-06-30

·

Updated

2024-06-15

·

CVE-2020-4044

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions xrdp-sesman versions prior to 0.9.13.1
Description The issue is related to a buffer overflow attack that can crash the xrdp-sesman service by connecting over port 3350 and supplying a malicious payload. Once the service is down, an unprivileged attacker can start an imposter sesman service, allowing them to capture user credentials submitted to XRDP, approve or reject arbitrary login credentials, and potentially hijack existing xorgxrdp sessions. This may also pose a risk of arbitrary code execution.
Recommendations For versions prior to 0.9.13.1, update to version 0.9.13.1 or later to resolve the issue. As a temporary workaround, consider restricting access to port 3350 to minimize the risk of exploitation.

Fix

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2258
ALT-PU-2020-2333
BDU:2021-03635
CVE-2020-4044
DLA-2319-1
DSA-4737-1
GHSA-J9FV-6FWF-P3G4
MGASA-2021-0016
OPENSUSE-SU-2020:0999-1
OPENSUSE-SU-2020:1200-1
OPENSUSE-SU-2020_0999-1
OPENSUSE-SU-2020_1200-1
OPENSUSE-SU-2024:11526-1
SUSE-SU-2020:1918-1
SUSE-SU-2020:1933-1
SUSE-SU-2020:1943-1
SUSE-SU-2020:1991-1
SUSE-SU-2020:2142-1
SUSE-SU-2020_1918-1
SUSE-SU-2020_1933-1
SUSE-SU-2020_1991-1
SUSE-SU-2020_2142-1
USN-6469-1

Affected Products

Alt Linux
Linuxmint
Suse
Ubuntu
Xrdp-Sesman