CVE-2022-23613
Summary
| CVE | CVE-2022-23613 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-02-07 22:15:00 UTC |
| Updated | 2023-11-07 03:44:00 UTC |
| Description | xrdp is an open source remote desktop protocol (RDP) server. In affected versions an integer underflow leading to a heap overflow in the sesman server allows any unauthenticated attacker which is able to locally access a sesman server to execute code as root. This vulnerability has been patched in version 0.9.18.1 and above. Users are advised to upgrade. There are no known workarounds. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 35 Update: xrdp-0.9.18-5.fc35 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 34 Update: xrdp-0.9.18-5.fc34 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 34 Update: xrdp-0.9.18-5.fc34 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| Merge pull request from GHSA-8h98-h426-xf32 · neutrinolabs/xrdp@4def30a · GitHub |
MISC |
github.com |
|
| Privilege escalation on xrdp-sesman · Advisory · neutrinolabs/xrdp · GitHub |
CONFIRM |
github.com |
|
| [SECURITY] Fedora 35 Update: xrdp-0.9.18-5.fc35 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 182752 Debian Security Update for xrdp (CVE-2022-23613)
- 199917 Ubuntu Security Notification for xrdp Vulnerabilities (USN-6474-1)
- 282403 Fedora Security Update for xrdp (FEDORA-2022-4283d4695d)
- 282404 Fedora Security Update for xrdp (FEDORA-2022-727e3914e1)
- 502203 Alpine Linux Security Update for xrdp
- 690788 Free Berkeley Software Distribution (FreeBSD) Security Update for xrdp (fc2a9541-8893-11ec-9d01-80ee73419af3)