UBUNTU-CVE-2024-39917
Dashboard / Vulnerabilities / UBUNTU-CVE-2024-39917
UBUNTU-CVE-2024-39917
Summary:
Details: xrdp is an open source RDP server. xrdp versions prior to 0.10.0 have a vulnerability that allows attackers to make an infinite number of login attempts. The number of max login attempts is supposed to be limited by a configuration parameter `MaxLoginRetry` in `/etc/xrdp/sesman.ini`. However, this mechanism was not effectively working. As a result, xrdp allows an infinite number of login attempts.
References: https://ubuntu.com/security/CVE-2024-39917, https://www.cve.org/CVERecord?id=CVE-2024-39917, https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-7w22-h4w7-8j5j, https://ubuntu.com/security/notices/USN-8476-1
Affected packages
Package
Name: xrdp
Purl: pkg:deb/ubuntu/xrdp?arch=source&distro=esm-apps%2Fbionic
Affected ranges
Type: ECOSYSTEM
Events:
