USN-6469-1: xrdp vulnerability
2 November 2023
xrdp could be made to crash or run programs if it received specially crafted network traffic.
Releases
Packages
- xrdp - Remote Desktop Protocol (RDP) server
Details
Ashley Newson discovered that xrdp incorrectly handled memory when
processing certain incoming connections. An attacker could possibly use
this issue to cause a denial of service or arbitrary code execution.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 20.04
Ubuntu 18.04
-
xrdp
-
0.9.5-2ubuntu0.1~esm1
Available with Ubuntu Pro
Ubuntu 16.04
-
xrdp
-
0.6.1-2ubuntu0.3+esm2
Available with Ubuntu Pro
Ubuntu 14.04
-
xrdp
-
0.6.0-1ubuntu0.1+esm2
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.