First published: Thu Jan 15 2009(Updated: )
Buffer overflow in the xrdp_bitmap_invalidate function in xrdp/xrdp_bitmap.c in xrdp 0.4.1 and earlier allows remote attackers to execute arbitrary code via a crafted request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
xrdp | =0.4 | |
xrdp | =0.3.2 | |
xrdp | =0.3 | |
xrdp | <=0.4.1 | |
xrdp | =0.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-5902 has a high severity rating due to its potential to allow remote attackers to execute arbitrary code.
To fix CVE-2008-5902, upgrade xrdp to version 0.4.2 or later.
CVE-2008-5902 affects xrdp versions 0.4.1 and earlier, including 0.4, 0.3.2, 0.3.1, and 0.3.
CVE-2008-5902 can be exploited by sending a crafted request that triggers a buffer overflow in the xrdp_bitmap_invalidate function.
Any user running affected versions of xrdp is at risk from CVE-2008-5902 due to the vulnerability's ability to allow remote code execution.