PT-2020-6234 · Xrdp+4 · Xrdp-Sesman+4
Ashley Newson
·
Published
2020-06-30
·
Updated
2024-06-15
·
CVE-2020-4044
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
xrdp-sesman versions prior to 0.9.13.1
Description
The issue is related to a buffer overflow attack that can crash the xrdp-sesman service by connecting over port 3350 and supplying a malicious payload. Once the service is down, an unprivileged attacker can start an imposter sesman service, allowing them to capture user credentials submitted to XRDP, approve or reject arbitrary login credentials, and potentially hijack existing xorgxrdp sessions. This may also pose a risk of arbitrary code execution.
Recommendations
For versions prior to 0.9.13.1, update to version 0.9.13.1 or later to resolve the issue.
As a temporary workaround, consider restricting access to port 3350 to minimize the risk of exploitation.
Fix
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Linuxmint
Suse
Ubuntu
Xrdp-Sesman