漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
xrdp: Pre-authentication out-of-bounds reads in RDP capability and channel parsers
Vulnerability Description
xrdp is an open source RDP server. Versions through 0.10.5 contain an out-of-bounds read vulnerability during the RDP capability exchange phase. The issue occurs when memory is accessed before validating the remaining buffer length. A remote, unauthenticated attacker can trigger this vulnerability by sending a specially crafted Confirm Active PDU. Successful exploitation could lead to a denial of service (process crash) or potential disclosure of sensitive information from the process memory. This issue has been fixed in version 0.10.6.
CVSS Information
N/A
Vulnerability Type
跨界内存读
Vulnerability Title
xrdp 安全漏洞
Vulnerability Description
xrdp是neutrinolabs开源的一款开源远程桌面协议服务器。 xrdp 0.10.5及之前版本存在安全漏洞,该漏洞源于RDP能力交换阶段存在越界读取,可能导致拒绝服务或泄露进程内存中的敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A