DLA-3375-1

Source
https://storage.googleapis.com/debian-osv/dla-osv/DLA-3375-1.json
Aliases
  • CVE-2022-23480
  • CVE-2022-23481
  • CVE-2022-23482
Published
2023-03-31T00:00:00Z
Modified
2023-03-31T13:15:19.063852Z
Details

It was discovered that there were a number of vulnerabilies in the xrdp Remote Desktop Protocol (RDP) server:

  • CVE-2022-23480: Prevent a series of potential buffer overflow vulnerabilities in the devredir_proc_client_devlist_announce_req() function.
  • CVE-2022-23481: Fix an out-of-bounds read vulnerability in the xrdp_caps_process_confirm_active() function.
  • CVE-2022-23480: Fix an out-of-bounds read vulnerability in the xrdp_sec_process_mcs_data_CS_CORE() function.

For Debian 10 Buster, these problems have been fixed in version 0.9.9-1+deb10u3.

We recommend that you upgrade your xrdp packages.

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS

References

Affected packages

Debian:10 / xrdp

xrdp

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0
Fixed
0.9.9-1+deb10u3

Affected versions

0.*

0.9.9-1
0.9.9-1+deb10u1
0.9.9-1+deb10u2