CVE-2022-23493: Out of Bound Read in xrdp
Published Dec 9, 2022
·Updated
xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a Out of Bound Read in xrdpmmtransprocessdrdynvcchannelclose() function. There are no known workarounds for this issue. Users are advised to upgrade.
Affected Software
3 affected componentsFixes available
debian/xrdp<=0.9.9-1+deb10u1
0.9.9-1+deb10u30.9.21.1-1~deb11u10.9.21.1-1
Neutrinolabs Xrdp<0.9.21
Debian Debian Linux=11.0
Event History
Dec 9, 2022
CVE Published
via MITRE·05:48 PM
Data Sourced
via MITRE·05:48 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this xrdp vulnerability?
The vulnerability ID of this xrdp vulnerability is CVE-2022-23493.
2
What is xrdp?
xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP).
3
What is the severity of CVE-2022-23493?
The severity of CVE-2022-23493 is critical with a severity score of 9.1 (out of 10).
4
What is the affected software?
The affected software is xrdp versions earlier than v0.9.21.
5
How can I fix the xrdp vulnerability (CVE-2022-23493)?
To fix the xrdp vulnerability (CVE-2022-23493), users are advised to update to xrdp version 0.9.21 or later.