-----BEGIN PGP SIGNATURE-----
wsF5BAABCAAjFiEEhC9y9XdAFQPCvYXchGmXSGiknnUFAmVDiWIFAwAAAAAACgkQhGmXSGiknnVe
Cw//Ti182aEhRP8QNNd9n8FZhlTY4KryCFb5h46yi50Xg35bjYtL4Fk2JTFKoxgolmlHHdY1dZn0
e7M1QdBufYTjaoJg7AIOIDFpSTWl6CpFujEyHw9QFxBSOd0npdKc9t8UNekUnxGF9CqN85svMtR+
VdeEvbqc3OrU9MtOVOQeY2c19CGe3M0KVvQZyi7+koH6MKsMrnX86zyEGqkMApyoHqyzGo189C6H
lW97mjuIyZOulpg8kjSYYi+ZNJ9oh2saWbdOxaCLbtFTvMcw9Y9e8ARAKift53aGg6JEQZTmoLyN
xuFNaE1rZUtesQYhVhbOpSnyYKjtPZX1vOCLARl4v0isGidB5Wrhrp1H5jpi8cuUiYdDkzyM9awa
+upm1XK+945YHqQMMbOv/37m+ANK1/nczwUWnjdS5gZRNbBL8t+4NBL6DzP7limlRihSNOVwXzEo
/ZvTWmHnqiRVarAaBy4oYkGWNqSlxgIBaoz5tdgR0IymAfXurYnwUxuXA2JQZK4hXafQnsmBWjEy
nCuCfNDEs2meGZguZN4TCzxAi+gssWxwsQL56jfBldawWhYcAo846k6F3FBaAjQqDfKg3PdfMImJ
2+62xKXSqEmn4jblkE3ld/6inaJZUFaUEWKLYs2Kt16HHM0ygIEMvco92jYOVp44yU9WItUX+Zs9
Thc=
=b5LU
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6469-1
November 02, 2023
xrdp vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS (Available with Ubuntu Pro)
- Ubuntu 16.04 LTS (Available with Ubuntu Pro)
- Ubuntu 14.04 LTS (Available with Ubuntu Pro)
Summary:
xrdp could be made to crash or run programs if it received
specially crafted network traffic.
Software Description:
- xrdp: Remote Desktop Protocol (RDP) server
Details:
Ashley Newson discovered that xrdp incorrectly handled memory when
processing certain incoming connections. An attacker could possibly use
this issue to cause a denial of service or arbitrary code execution.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 20.04 LTS:
xrdp 0.9.12-1ubuntu0.1
Ubuntu 18.04 LTS (Available with Ubuntu Pro):
xrdp 0.9.5-2ubuntu0.1~esm1
Ubuntu 16.04 LTS (Available with Ubuntu Pro):
xrdp 0.6.1-2ubuntu0.3+esm2
Ubuntu 14.04 LTS (Available with Ubuntu Pro):
xrdp 0.6.0-1ubuntu0.1+esm2
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-6469-1
CVE-2020-4044
Package Information:
https://launchpad.net/ubuntu/+source/xrdp/0.9.12-1ubuntu0.1
No comments:
Post a Comment