CVE-2008-5903: High severity xrdp xrdp vulnerability
Published Jan 15, 2009
·Updated
Array index error in the xrdpbitmapdefproc function in xrdp/funcs.c in xrdp 0.4.1 and earlier allows remote attackers to execute arbitrary code via vectors that manipulate the value of the editpos structure member.
Affected Software
5 affected components
xrdp xrdp=0.4
xrdp xrdp=0.3.2
xrdp xrdp=0.3
xrdp xrdp<=0.4.1
xrdp xrdp=0.3.1
Event History
Jan 15, 2009
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
via NVD·05:30 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2008-5903?
CVE-2008-5903 is classified as a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2008-5903?
To fix CVE-2008-5903, upgrade xrdp to version 0.4.2 or later, which addresses this vulnerability.
3
What systems are affected by CVE-2008-5903?
CVE-2008-5903 affects xrdp versions 0.4.1 and earlier, including 0.3.x series.
4
What type of vulnerability is CVE-2008-5903?
CVE-2008-5903 is an array index error vulnerability that allows for arbitrary code execution by remote attackers.
5
Can CVE-2008-5903 lead to system takeover?
Yes, CVE-2008-5903 can potentially allow attackers to take control of the affected systems.