Debian LTS: DLA-3370-1: xrdp security update
Summary
xrdp < v0.9.21 contain a buffer over flow in xrdp_login_wnd_create() function.
There are no known workarounds for this issue.
CVE-2022-23478
xrdp < v0.9.21 contain a Out of Bound Write in
xrdp_mm_trans_process_drdynvc_channel_open() function. There are no known
workarounds for this issue.
CVE-2022-23479
xrdp < v0.9.21 contain a buffer over flow in xrdp_mm_chan_data_in() function.
There are no known workarounds for this issue.
CVE-2022-23483
xrdp < v0.9.21 contain a Out of Bound Read in libxrdp_send_to_channel() function.
There are no known workarounds for this issue.
CVE-2022-23484
xrdp < v0.9.21 contain a Integer Overflow in xrdp_mm_process_rail_update_window_text()
function. There are no known workarounds for this issue.
CVE-2022-23493
xrdp < v0.9.21 contain a Out of Bound Read in xrdp_mm_trans_process_drdynvc_channel_close()
function. There are no known workarounds for this issue.
For Debian 10 buster, these problems have been f...