CVE-2020-4044

Source
https://nvd.nist.gov/vuln/detail/CVE-2020-4044
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-4044.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2020-4044
Related
Published
2020-06-30T16:15:16Z
Modified
2025-01-15T01:45:44.515109Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

The xrdp-sesman service before version 0.9.13.1 can be crashed by connecting over port 3350 and supplying a malicious payload. Once the xrdp-sesman process is dead, an unprivileged attacker on the server could then proceed to start their own imposter sesman service listening on port 3350. This will allow them to capture any user credentials that are submitted to XRDP and approve or reject arbitrary login credentials. For xorgxrdp sessions in particular, this allows an unauthorized user to hijack an existing session. This is a buffer overflow attack, so there may be a risk of arbitrary code execution as well.

References

Affected packages

Debian:11 / xrdp

Package

Name
xrdp
Purl
pkg:deb/debian/xrdp?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.9.12-1.1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / xrdp

Package

Name
xrdp
Purl
pkg:deb/debian/xrdp?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.9.12-1.1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / xrdp

Package

Name
xrdp
Purl
pkg:deb/debian/xrdp?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.9.12-1.1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Git / github.com/neutrinolabs/xrdp

Affected ranges

Type
GIT
Repo
https://github.com/neutrinolabs/xrdp
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed

Affected versions

v0.*

v0.9.1
v0.9.10
v0.9.11
v0.9.12
v0.9.13
v0.9.2
v0.9.3
v0.9.3.rc1
v0.9.4
v0.9.4.rc1
v0.9.5
v0.9.6
v0.9.7
v0.9.8
v0.9.9