First published: Mon Jul 05 2021(Updated: )
In the xrdp package (in branches through 3.14) for Alpine Linux, RDP sessions are vulnerable to man-in-the-middle attacks because pre-generated RSA certificates and private keys are used.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Alpine Linux Aports | <=3.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2021-36158.
The severity of CVE-2021-36158 is medium (5.9).
The affected software for CVE-2021-36158 is the xrdp package (in branches through 3.14) for Alpine Linux.
CVE-2021-36158 poses a risk of man-in-the-middle attacks on RDP sessions in Alpine Linux.
Yes, please refer to the official Alpine Linux Aports repository for the fix to CVE-2021-36158.