漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
xrdp: lib_framebuffer_update Has Integer Overflow Heap Info Leak & ASLR Bypass
Vulnerability Description
xrdp is an open source RDP server. Versions 0.10.6 and prior contain an integer overflow vulnerability when processing screen update messages within the vnc-any connection mode. A malicious remote VNC server can send crafted image dimensions that cause an integer overflow during memory buffer size calculation, resulting in an undersized allocation. Subsequent processing of the incoming image data using the original oversized parameters leads to an out-of-bounds read. An unauthenticated remote attacker could exploit this flaw to disclose sensitive information from the heap memory or cause a denial of service (DoS) via a process crash. This issue has been fixed in version 0.10.6.1.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
Vulnerability Type
整数溢出或超界折返
Vulnerability Title
neutrinolabs xrdp 数字错误漏洞
Vulnerability Description
neutrinolabs xrdp是neutrinolabs团队开源的一款开源远程桌面协议服务器。 neutrinolabs xrdp 0.10.6及之前版本存在数字错误漏洞,该漏洞源于在处理vnc-any连接模式中的屏幕更新消息时存在整数溢出,可能导致未经身份验证的远程攻击者利用特制图像尺寸导致内存缓冲区大小计算错误,造成越界读取,从而泄露堆内存敏感信息或通过进程崩溃导致拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A