2022-02-12
ALT-BU-2022-3987-1
Branch p10 update bulletin.
Closed bugs
libapt кэширует информацию о подключенных репозиториях без API для её удаления или обновления
Closed vulnerabilities
Published: 2022-02-10
BDU:2022-05759
Уязвимость сервера XRDP, связанная с целочисленной потерей значимости, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
Severity: HIGH (7.8)
Vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References:
Published: 2022-02-08
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2022-23613
xrdp is an open source remote desktop protocol (RDP) server. In affected versions an integer underflow leading to a heap overflow in the sesman server allows any unauthenticated attacker which is able to locally access a sesman server to execute code as root. This vulnerability has been patched in version 0.9.18.1 and above. Users are advised to upgrade. There are no known workarounds.
Severity: HIGH (7.8)
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References:
- https://github.com/neutrinolabs/xrdp/commit/4def30ab8ea445cdc06832a44c3ec40a506a0ffa
- https://github.com/neutrinolabs/xrdp/commit/4def30ab8ea445cdc06832a44c3ec40a506a0ffa
- https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-8h98-h426-xf32
- https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-8h98-h426-xf32
- FEDORA-2022-727e3914e1
- FEDORA-2022-727e3914e1
- FEDORA-2022-4283d4695d
- FEDORA-2022-4283d4695d