Anfälligkeitssuche        Suche in 191973 CVE Beschreibungen
und 86218 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.892319
Kategorie:Debian Local Security Checks
Titel:Debian LTS: Security Advisory for xrdp (DLA-2319-1)
Zusammenfassung:The remote host is missing an update for the 'xrdp'; package(s) announced via the DLA-2319-1 advisory.
Beschreibung:Summary:
The remote host is missing an update for the 'xrdp'
package(s) announced via the DLA-2319-1 advisory.

Vulnerability Insight:
xrdp-sesman service in xrdp can be crashed by connecting over port 3350
and supplying a malicious payload. Once the xrdp-sesman process is dead,
an unprivileged attacker on the server could then proceed to start their
own imposter sesman service listening on port 3350. This will allow them
to capture any user credentials that are submitted to XRDP and approve or
reject arbitrary login credentials. For xorgxrdp sessions in particular,
this allows an unauthorized user to hijack an existing session. This is a
buffer overflow attack, so there may be a risk of arbitrary code
execution as well.

Affected Software/OS:
'xrdp' package(s) on Debian Linux.

Solution:
For Debian 9 stretch, this problem has been fixed in version
0.9.1-9+deb9u4.

We recommend that you upgrade your xrdp packages.

CVSS Score:
4.6

CVSS Vector:
AV:L/AC:L/Au:N/C:P/I:P/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2020-4044
https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-j9fv-6fwf-p3g4
Debian Security Information: DSA-4737 (Google Search)
https://www.debian.org/security/2020/dsa-4737
https://github.com/neutrinolabs/xrdp/commit/0c791d073d0eb344ee7aaafd221513dc9226762c
https://github.com/neutrinolabs/xrdp/releases/tag/v0.9.13.1
https://lists.debian.org/debian-lts-announce/2020/08/msg00015.html
SuSE Security Announcement: openSUSE-SU-2020:0999 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00036.html
SuSE Security Announcement: openSUSE-SU-2020:1200 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00037.html
CopyrightCopyright (C) 2020 Greenbone Networks GmbH

Dies ist nur einer von 86218 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2020 E-Soft Inc. Alle Rechte vorbehalten.