CVE-2023-40184
Summary
| CVE | CVE-2023-40184 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-08-30 18:15:00 UTC |
| Updated | 2023-09-15 22:15:00 UTC |
| Description | xrdp is an open source remote desktop protocol (RDP) server. In versions prior to 0.9.23 improper handling of session establishment errors allows bypassing OS-level session restrictions. The `auth_start_session` function can return non-zero (1) value on, e.g., PAM error which may result in in session restrictions such as max concurrent sessions per user by PAM (ex ./etc/security/limits.conf) to be bypassed. Users (administrators) don't use restrictions by PAM are not affected. This issue has been addressed in release version 0.9.23. Users are advised to upgrade. There are no known workarounds for this issue. |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|
| Application |
Neutrinolabs |
Xrdp |
All |
All |
All |
All |
References
| Reference | Source | Link | Tags |
|---|
| github.com/neutrinolabs/xrdp/blame/9bbb2ec68f390504c32f2062847aa3d821a00... |
MISC |
github.com |
|
| Merge pull request from GHSA-f489-557v-47jq · neutrinolabs/xrdp@a111a0f · GitHub |
MISC |
github.com |
|
| [SECURITY] Fedora 38 Update: xrdp-0.9.23-1.fc38 - package-announce - Fedora Mailing-Lists |
MISC |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 37 Update: xrdp-0.9.23-1.fc37 - package-announce - Fedora Mailing-Lists |
MISC |
lists.fedoraproject.org |
|
| Improper handling of session establishment errors allows bypassing OS-level session restrictions · Advisory · neutrinolabs/xrdp · GitHub |
MISC |
github.com |
|
| [SECURITY] Fedora 39 Update: xrdp-0.9.23-1.fc39 - package-announce - Fedora Mailing-Lists |
MISC |
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 199917 Ubuntu Security Notification for xrdp Vulnerabilities (USN-6474-1)
- 285273 Fedora Security Update for xrdp (FEDORA-2023-5134642a68)
- 506279 Alpine Linux Security Update for xrdp
- 691309 Free Berkeley Software Distribution (FreeBSD) Security Update for xrdp (c9ff1150-5d63-11ee-bbae-1c61b4739ac9)
- 754908 SUSE Enterprise Linux Security Update for xrdp (SUSE-SU-2023:3735-1)
- 754960 SUSE Enterprise Linux Security Update for xrdp (SUSE-SU-2023:3830-1)