xrdp 0.9.1 calls the PAM function authstartsession() in an incorrect location, leading to PAM session modules not being properly initialized, with a potential consequence of incorrect configurations or elevation of privileges, aka a pam_limits.so bypass.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "0.9.5-2", "binary_name": "xorgxrdp" }, { "binary_version": "0.9.5-2", "binary_name": "xorgxrdp-dbgsym" }, { "binary_version": "0.9.5-2", "binary_name": "xrdp" }, { "binary_version": "0.9.5-2", "binary_name": "xrdp-dbgsym" }, { "binary_version": "0.9.5-2", "binary_name": "xrdp-pulseaudio-installer" } ] }