PT-2022-5896 · Xrdp+6 · Xrdp+6
Metalefty
·
Published
2022-12-09
·
Updated
2024-06-15
·
CVE-2022-23468
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
xrdp versions prior to 0.9.21
Description
The issue is related to a buffer overflow in the
xrdp login wnd create() function of the xrdp server, which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). This buffer overflow is caused by the lack of input size validation, allowing a remote attacker to potentially execute arbitrary code. There are no known workarounds for this issue.Recommendations
To resolve the issue, users are advised to upgrade to a version of xrdp that is 0.9.21 or later. As a temporary workaround, consider disabling the
xrdp login wnd create() function until a patch is available. However, the most effective solution is to upgrade to the latest version of xrdp.Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Linuxmint
Red Os
Suse
Ubuntu
Xrdp