Anfälligkeitssuche        Suche in 191973 CVE Beschreibungen
und 86218 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:
Kategorie:Debian Local Security Checks
Titel:Debian LTS: Security Advisory for xrdp (DLA-2319-1)
Zusammenfassung:The remote host is missing an update for the 'xrdp'; package(s) announced via the DLA-2319-1 advisory.
The remote host is missing an update for the 'xrdp'
package(s) announced via the DLA-2319-1 advisory.

Vulnerability Insight:
xrdp-sesman service in xrdp can be crashed by connecting over port 3350
and supplying a malicious payload. Once the xrdp-sesman process is dead,
an unprivileged attacker on the server could then proceed to start their
own imposter sesman service listening on port 3350. This will allow them
to capture any user credentials that are submitted to XRDP and approve or
reject arbitrary login credentials. For xorgxrdp sessions in particular,
this allows an unauthorized user to hijack an existing session. This is a
buffer overflow attack, so there may be a risk of arbitrary code
execution as well.

Affected Software/OS:
'xrdp' package(s) on Debian Linux.

For Debian 9 stretch, this problem has been fixed in version

We recommend that you upgrade your xrdp packages.

CVSS Score:

CVSS Vector:

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2020-4044
Debian Security Information: DSA-4737 (Google Search)
SuSE Security Announcement: openSUSE-SU-2020:0999 (Google Search)
SuSE Security Announcement: openSUSE-SU-2020:1200 (Google Search)
CopyrightCopyright (C) 2020 Greenbone Networks GmbH

Dies ist nur einer von 86218 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.

© 1998-2020 E-Soft Inc. Alle Rechte vorbehalten.