Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
xrdp: lib_framebuffer_update Has Integer Overflow Heap Info Leak & ASLR Bypass
Vulnerability Description
xrdp is an open source RDP server. Versions 0.10.6 and prior contain an integer overflow vulnerability when processing screen update messages within the vnc-any connection mode. A malicious remote VNC server can send crafted image dimensions that cause an integer overflow during memory buffer size calculation, resulting in an undersized allocation. Subsequent processing of the incoming image data using the original oversized parameters leads to an out-of-bounds read. An unauthenticated remote attacker could exploit this flaw to disclose sensitive information from the heap memory or cause a denial of service (DoS) via a process crash. This issue has been fixed in version 0.10.6.1.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
Vulnerability Type
整数溢出或超界折返
Vulnerability Title
neutrinolabs xrdp 数字错误漏洞
Vulnerability Description
neutrinolabs xrdp是neutrinolabs团队开源的一款开源远程桌面协议服务器。 neutrinolabs xrdp 0.10.6及之前版本存在数字错误漏洞,该漏洞源于在处理vnc-any连接模式中的屏幕更新消息时存在整数溢出,可能导致未经身份验证的远程攻击者利用特制图像尺寸导致内存缓冲区大小计算错误,造成越界读取,从而泄露堆内存敏感信息或通过进程崩溃导致拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A