MGASA-2023-0002

Source
https://advisories.mageia.org/MGASA-2023-0002.html
Import Source
https://advisories.mageia.org/MGASA-2023-0002.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2023-0002
Upstream
Published
2023-01-13T17:37:09Z
Modified
2026-04-16T04:44:18Z
Summary
Updated xrdp packages fix security vulnerability
Details

xrdp less than v0.9.21 contain a buffer over flow in xrdp_login_wnd_create() function. (CVE-2022-23468)

xrdp less than v0.9.21 contain a buffer over flow in audin_send_open() function. (CVE-2022-23477)

xrdp less than v0.9.21 contain a Out of Bound Write in xrdp_mm_trans_process_drdynvc_channel_open() function. (CVE-2022-23478)

xrdp less than v0.9.21 contain a buffer over flow in xrdp_mm_chan_data_in() function. (CVE-2022-23479)

xrdp less than v0.9.21 contain a buffer over flow in devredir_proc_client_devlist_announce_req() function. (CVE-2022-23480)

xrdp less than v0.9.21 contain a Out of Bound Read in xrdp_caps_process_confirm_active() function. (CVE-2022-23481)

xrdp less than v0.9.21 contain a Out of Bound Read in xrdp_sec_process_mcs_data_CS_CORE() function. (CVE-2022-23482)

xrdp less than v0.9.21 contain a Out of Bound Read in libxrdp_send_to_channel() function. (CVE-2022-23483)

xrdp less than v0.9.21 contain a Integer Overflow in xrdp_mm_process_rail_update_window_text() function. (CVE-2022-23484)

xrdp less than v0.9.21 contain a Out of Bound Read in xrdp_mm_trans_process_drdynvc_channel_close() function. (CVE-2022-23493)

References
Credits

Affected packages

Mageia:8 / xrdp

Package

Name
xrdp
Purl
pkg:rpm/mageia/xrdp?arch=source&distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.9.21-1.mga8

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2023-0002.json"