Mageia 2023-0002: xrdp security update
Summary
xrdp less than v0.9.21 contain a buffer over flow in
xrdp_login_wnd_create() function. (CVE-2022-23468)
xrdp less than v0.9.21 contain a buffer over flow in audin_send_open()
function. (CVE-2022-23477)
xrdp less than v0.9.21 contain a Out of Bound Write in
xrdp_mm_trans_process_drdynvc_channel_open() function. (CVE-2022-23478)
xrdp less than v0.9.21 contain a buffer over flow in
xrdp_mm_chan_data_in() function. (CVE-2022-23479)
xrdp less than v0.9.21 contain a buffer over flow in
devredir_proc_client_devlist_announce_req() function. (CVE-2022-23480)
xrdp less than v0.9.21 contain a Out of Bound Read in
xrdp_caps_process_confirm_active() function. (CVE-2022-23481)
xrdp less than v0.9.21 contain a Out of Bound Read in
xrdp_sec_process_mcs_data_CS_CORE() function. (CVE-2022-23482)
xrdp less than v0.9.21 contain a Out of Bound Read in
libxrdp_send_to_channel() function. (CVE-2022-23483)
xrdp less than v0.9.21 contain a Integer Overflow in
xrdp_mm_process_rail_update_window_text() functi...
References
- https://bugs.mageia.org/show_bug.cgi?id=31309
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/67CHZVOMSTH2Q7P3TYFUNZUA6J7ZYEBQ/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23468
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23477
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23478
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23479
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23480
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23481
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23482
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23483
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23484
Resolution
MGASA-2023-0002 - Updated xrdp packages fix security vulnerability
SRPMS
- 8/core/xrdp-0.9.21-1.mga8