SUSE-SU-2023:0340-1
Dashboard / Vulnerabilities / SUSE-SU-2023:0340-1
SUSE-SU-2023:0340-1
Summary: Security update for xrdp
Details: This update for xrdp fixes the following issues: - CVE-2022-23468: Fixed a buffer overflow in xrdp_login_wnd_create() (bsc#1206300). - CVE-2022-23479: Fixed a buffer overflow in xrdp_mm_chan_data_in() (bsc#1206303). - CVE-2022-23480: Fixed a buffer overflow in devredir_proc_client_devlist_announce_req() (bsc#1206306). - CVE-2022-23481: Fixed an out of bound read in xrdp_caps_process_confirm_active() (bsc#1206307). - CVE-2022-23482: Fixed an out of bound read in xrdp_sec_process_mcs_data_CS_CORE() (bsc#1206310). - CVE-2022-23483: Fixed an out of bound read in libxrdp_send_to_channel() (bsc#1206311). - CVE-2022-23484: Fixed a integer overflow in xrdp_mm_process_rail_update_window_text() (bsc#1206312).
References: https://www.suse.com/support/update/announcement/2023/suse-su-20230340-1/, https://bugzilla.suse.com/1206300, https://bugzilla.suse.com/1206303, https://bugzilla.suse.com/1206306, https://bugzilla.suse.com/1206307, https://bugzilla.suse.com/1206310, https://bugzilla.suse.com/1206311, https://bugzilla.suse.com/1206312, https://www.suse.com/security/cve/CVE-2022-23468, https://www.suse.com/security/cve/CVE-2022-23479, https://www.suse.com/security/cve/CVE-2022-23480, https://www.suse.com/security/cve/CVE-2022-23481, https://www.suse.com/security/cve/CVE-2022-23482, https://www.suse.com/security/cve/CVE-2022-23483, https://www.suse.com/security/cve/CVE-2022-23484
Affected packages
Package
Name: xrdp
Purl: pkg:rpm/suse/xrdp&distro=SUSE%20OpenStack%20Cloud%209
Affected ranges
Type: ECOSYSTEM
Events:
