CVE-2008-5904: Input Validation
Published Jan 15, 2009
·Updated
The rdprdpprocesscolorpointerpdu function in rdp/rdprdp.c in xrdp 0.4.1 and earlier allows remote RDP servers to have an unknown impact via input data that sets crafted values for certain length variables, leading to a buffer overflow.
Affected Software
5 affected components
xrdp xrdp<=0.4.1
xrdp xrdp=0.3
xrdp xrdp=0.3.1
xrdp xrdp=0.3.2
xrdp xrdp=0.4
Event History
Jan 15, 2009
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
via NVD·05:30 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2008-5904?
CVE-2008-5904 is considered to have a potentially high severity due to its ability to cause a buffer overflow.
2
How do I fix CVE-2008-5904?
To fix CVE-2008-5904, you should update xrdp to version 0.4.2 or later.
3
What versions of xrdp are affected by CVE-2008-5904?
CVE-2008-5904 affects xrdp versions 0.4.1 and earlier, including 0.3, 0.3.1, and 0.3.2.
4
What is the impact of exploiting CVE-2008-5904?
Exploiting CVE-2008-5904 may allow remote attackers to execute arbitrary code on the affected system.
5
Is CVE-2008-5904 still a concern in modern systems?
CVE-2008-5904 can still be a concern if older versions of xrdp remain in use on systems that are not properly updated.