PT-2022-5896 · Xrdp+6 · Xrdp+6

Metalefty

·

Published

2022-12-09

·

Updated

2024-06-15

·

CVE-2022-23468

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions xrdp versions prior to 0.9.21
Description The issue is related to a buffer overflow in the xrdp login wnd create() function of the xrdp server, which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). This buffer overflow is caused by the lack of input size validation, allowing a remote attacker to potentially execute arbitrary code. There are no known workarounds for this issue.
Recommendations To resolve the issue, users are advised to upgrade to a version of xrdp that is 0.9.21 or later. As a temporary workaround, consider disabling the xrdp login wnd create() function until a patch is available. However, the most effective solution is to upgrade to the latest version of xrdp.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-3320
ALT-PU-2022-3387
ALT-PU-2022-3404
ALT-PU-2023-5781
BDU:2022-07312
CVE-2022-23468
DLA-3370-1
DSA-5502-1
GHSA-8C2F-MW8M-QPX6
MGASA-2023-0002
OPENSUSE-SU-2023_0033-1
OPENSUSE-SU-2024:12602-1
ROSA-SA-2023-2249
ROSA-SA-2023-2250
SUSE-SU-2023:0012-1
SUSE-SU-2023:0033-1
SUSE-SU-2023:0340-1
SUSE-SU-2023:0374-1
SUSE-SU-2023:0387-1
SUSE-SU-2023_0012-1
SUSE-SU-2023_0033-1
SUSE-SU-2023_0340-1
SUSE-SU-2023_0374-1
SUSE-SU-2023_0387-1
USN-6474-1

Affected Products

Alt Linux
Astra Linux
Linuxmint
Red Os
Suse
Ubuntu
Xrdp