漏洞信息详情
xrdp-sesman service 缓冲区错误漏洞
漏洞简介
xrdp-sesman service是一款开源的RDP(远程桌面协议)服务器。
xrdp-sesman service 0.9.13.1之前版本中存在缓冲区错误漏洞。远程攻击者可通过连接3350端口并提供恶意的payload利用该漏洞在系统上执行任意代码或导致应用程序崩溃(拒绝服务)。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-j9fv-6fwf-p3g4
参考网址
来源:DEBIAN
链接:https://www.debian.org/security/2020/dsa-4737
来源:MISC
链接:https://github.com/neutrinolabs/xrdp/releases/tag/v0.9.13.1
来源:SUSE
链接:http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00036.html
来源:SUSE
链接:http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00037.html
来源:MISC
链接:https://github.com/neutrinolabs/xrdp/commit/0c791d073d0eb344ee7aaafd221513dc9226762c
来源:MLIST
链接:https://lists.debian.org/debian-lts-announce/2020/08/msg00015.html
来源:CONFIRM
链接:https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-j9fv-6fwf-p3g4
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.2710/
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2020-4044
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.2734/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.2603/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.2454/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.2245/
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/xrdp-sesman-buffer-overflow-32878
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.2466/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.2510/
受影响实体
暂无
补丁
- xrdp-sesman service 缓冲区错误漏洞的修复措施<!--2020-6-30-->
还没有评论,来说两句吧...