Debian Security Advisory

DLA-3375-1 xrdp -- LTS security update

Date Reported:
31 Mar 2023
Affected Packages:
xrdp
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2022-23480, CVE-2022-23481, CVE-2022-23482.
More information:

It was discovered that there were a number of vulnerabilies in the xrdp Remote Desktop Protocol (RDP) server:

  • CVE-2022-23480: Prevent a series of potential buffer overflow vulnerabilities in the devredir_proc_client_devlist_announce_req() function.
  • CVE-2022-23481: Fix an out-of-bounds read vulnerability in the xrdp_caps_process_confirm_active() function.
  • CVE-2022-23480: Fix an out-of-bounds read vulnerability in the xrdp_sec_process_mcs_data_CS_CORE() function.

For Debian 10 Buster, these problems have been fixed in version 0.9.9-1+deb10u3.

We recommend that you upgrade your xrdp packages.

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS