CVE-2017-16927: Buffer Overflow
The scpv0saccept function in sesman/libscp/libscpv0.c in the session manager in xrdp through 0.9.4 uses an untrusted integer as a write length, which allows local users to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted input stream.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2017-16927?
CVE-2017-16927 is a vulnerability in the session manager in xrdp through 0.9.4 that allows local users to cause a denial of service or possibly have unspecified other impact.
What is the severity of CVE-2017-16927?
The severity of CVE-2017-16927 is high, with a CVSS score of 8.4.
What software is affected by CVE-2017-16927?
The Neutrinolabs Xrdp version up to and including 0.9.4 and Debian Linux version 7.0 are affected by CVE-2017-16927.
How can CVE-2017-16927 be exploited?
CVE-2017-16927 can be exploited by local users to cause a denial of service or possibly have unspecified other impact by crafting input to the session manager.
Are there any fixes or patches available for CVE-2017-16927?
Yes, the fix for CVE-2017-16927 is available in the form of a pull request on GitHub for the Neutrinolabs Xrdp project.