First published: Thu Jan 15 2009(Updated: )
The rdp_rdp_process_color_pointer_pdu function in rdp/rdp_rdp.c in xrdp 0.4.1 and earlier allows remote RDP servers to have an unknown impact via input data that sets crafted values for certain length variables, leading to a buffer overflow.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
xrdp | <=0.4.1 | |
xrdp | =0.3 | |
xrdp | =0.3.1 | |
xrdp | =0.3.2 | |
xrdp | =0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-5904 is considered to have a potentially high severity due to its ability to cause a buffer overflow.
To fix CVE-2008-5904, you should update xrdp to version 0.4.2 or later.
CVE-2008-5904 affects xrdp versions 0.4.1 and earlier, including 0.3, 0.3.1, and 0.3.2.
Exploiting CVE-2008-5904 may allow remote attackers to execute arbitrary code on the affected system.
CVE-2008-5904 can still be a concern if older versions of xrdp remain in use on systems that are not properly updated.