CVE-2008-5902: Buffer Overflow
Published Jan 15, 2009
·Updated
Buffer overflow in the xrdpbitmapinvalidate function in xrdp/xrdpbitmap.c in xrdp 0.4.1 and earlier allows remote attackers to execute arbitrary code via a crafted request.
Affected Software
5 affected components
xrdp xrdp=0.4
xrdp xrdp=0.3.2
xrdp xrdp=0.3
xrdp xrdp<=0.4.1
xrdp xrdp=0.3.1
Event History
Jan 15, 2009
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
via NVD·05:30 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2008-5902?
CVE-2008-5902 has a high severity rating due to its potential to allow remote attackers to execute arbitrary code.
2
How do I fix CVE-2008-5902?
To fix CVE-2008-5902, upgrade xrdp to version 0.4.2 or later.
3
What versions of xrdp are affected by CVE-2008-5902?
CVE-2008-5902 affects xrdp versions 0.4.1 and earlier, including 0.4, 0.3.2, 0.3.1, and 0.3.
4
What is the exploit method used in CVE-2008-5902?
CVE-2008-5902 can be exploited by sending a crafted request that triggers a buffer overflow in the xrdp_bitmap_invalidate function.
5
Who is impacted by CVE-2008-5902?
Any user running affected versions of xrdp is at risk from CVE-2008-5902 due to the vulnerability's ability to allow remote code execution.