xrdp 'sesman/verify_user.c' Remote Denial of Service Vulnerability
BID:72667
Info
xrdp 'sesman/verify_user.c' Remote Denial of Service Vulnerability
| Bugtraq ID: | 72667 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 18 2015 12:00AM |
| Updated: | Feb 18 2015 12:00AM |
| Credit: | Ken Milmore |
| Vulnerable: |
xrdp xrdp 0.4.1 xrdp xrdp 0.6.1 |
| Not Vulnerable: | |
Exploit / POC
xrdp 'sesman/verify_user.c' Remote Denial of Service Vulnerability
An attacker can exploit this issue using readily available tools.
An attacker can exploit this issue using readily available tools.
References
xrdp 'sesman/verify_user.c' Remote Denial of Service Vulnerability
References:
References:
- Re: [Xrdp-devel] Problems with non-PAM password authentication. (Ken Milmore)
- sesman: check for null from crypt() (xrdp)
- xrdp Home Page (xrdp)