CVE-2021-36158: Medium severity alpine linux aports vulnerability
Published Jul 5, 2021
·Updated
In the xrdp package (in branches through 3.14) for Alpine Linux, RDP sessions are vulnerable to man-in-the-middle attacks because pre-generated RSA certificates and private keys are used.
Affected Software
1 affected component
Alpinelinux Aports Alpine<=3.14
Remediation
Patch Available
Event History
Jul 5, 2021
CVE Published
via MITRE·10:36 PM
Data Sourced
via MITRE·10:36 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-36158.
2
What is the severity of CVE-2021-36158?
The severity of CVE-2021-36158 is medium (5.9).
3
What is the affected software for CVE-2021-36158?
The affected software for CVE-2021-36158 is the xrdp package (in branches through 3.14) for Alpine Linux.
4
What is the risk associated with CVE-2021-36158?
CVE-2021-36158 poses a risk of man-in-the-middle attacks on RDP sessions in Alpine Linux.
5
Is there a fix available for CVE-2021-36158?
Yes, please refer to the official Alpine Linux Aports repository for the fix to CVE-2021-36158.