Ubuntu 6474-1: xrdp vulnerabilities
Summary
A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS (Available with Ubuntu Pro) - Ubuntu 20.04 LTS (Available with Ubuntu Pro) - Ubuntu 18.04 LTS (Available with Ubuntu Pro) - Ubuntu 16.04 LTS (Available with Ubuntu Pro) - Ubuntu 14.04 LTS (Available with Ubuntu Pro) Summary: Several security issues were fixed in xrdp. Software Description: - xrdp: Remote Desktop Protocol (RDP) server Details: It was discovered that xrdp incorrectly handled validation of client-supplied data, which could lead to out-of-bounds reads. An attacker could possibly use this issue to crash the program or extract sensitive information. (CVE-2022-23479, CVE-2022-23481, CVE-2022-23483, CVE-2023-42822) It was discovered that xrdp improperly handled session establishment errors. An attacker could potentially use this issue to bypass the OS-level session restrictions by PAM. (CVE-2023-40184) It was discovered that xrdp incorrectly handled...
Read the Full AdvisoryUpdate Instructions
The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS (Available with Ubuntu Pro): xrdp 0.9.17-2ubuntu2+esm1 Ubuntu 20.04 LTS (Available with Ubuntu Pro): xrdp 0.9.12-1ubuntu0.1+esm1 Ubuntu 18.04 LTS (Available with Ubuntu Pro): xrdp 0.9.5-2ubuntu0.1~esm2 Ubuntu 16.04 LTS (Available with Ubuntu Pro): xrdp 0.6.1-2ubuntu0.3+esm3 Ubuntu 14.04 LTS (Available with Ubuntu Pro): xrdp 0.6.0-1ubuntu0.1+esm3 In general, a standard system update will make all the necessary changes.
References
https://ubuntu.com/security/notices/USN-6474-1
CVE-2022-23468, CVE-2022-23477, CVE-2022-23478, CVE-2022-23479,
CVE-2022-23480, CVE-2022-23481, CVE-2022-23482, CVE-2022-23483,
CVE-2022-23484, CVE-2022-23493, CVE-2022-23613, CVE-2023-40184,
CVE-2023-42822
Package Information