Búsqueda de    
    Buscar 191973 Descripciones CVE y
86218 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:
Categoría:Debian Local Security Checks
Título:Debian LTS: Security Advisory for xrdp (DLA-2319-1)
Resumen:The remote host is missing an update for the 'xrdp'; package(s) announced via the DLA-2319-1 advisory.
The remote host is missing an update for the 'xrdp'
package(s) announced via the DLA-2319-1 advisory.

Vulnerability Insight:
xrdp-sesman service in xrdp can be crashed by connecting over port 3350
and supplying a malicious payload. Once the xrdp-sesman process is dead,
an unprivileged attacker on the server could then proceed to start their
own imposter sesman service listening on port 3350. This will allow them
to capture any user credentials that are submitted to XRDP and approve or
reject arbitrary login credentials. For xorgxrdp sessions in particular,
this allows an unauthorized user to hijack an existing session. This is a
buffer overflow attack, so there may be a risk of arbitrary code
execution as well.

Affected Software/OS:
'xrdp' package(s) on Debian Linux.

For Debian 9 stretch, this problem has been fixed in version

We recommend that you upgrade your xrdp packages.

CVSS Score:

CVSS Vector:

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2020-4044
Debian Security Information: DSA-4737 (Google Search)
SuSE Security Announcement: openSUSE-SU-2020:0999 (Google Search)
SuSE Security Announcement: openSUSE-SU-2020:1200 (Google Search)
CopyrightCopyright (C) 2020 Greenbone Networks GmbH

Esta es sólo una de 86218 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.

© 1998-2020 E-Soft Inc. Todos los derechos reservados.