Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
xrdp: Channel Data Forwarding Fixed-Size Buffer Overflow
Vulnerability Description
xrdp is an open source RDP server. Versions 0.10.6 and prior contain a heap-based buffer overflow vulnerability within the virtual channel forwarding mechanism. When forwarding data from a remote client to the internal channel server, the xrdp process utilizes a fixed-size buffer without adequate bounds checking on the incoming payload. An authenticated remote attacker can exploit this flaw by sending a specially crafted virtual channel message that exceeds the buffer capacity, leading to heap memory corruption. This may result in a denial of service or the execution of arbitrary code with the privileges of the xrdp process. This issue has been fixed in version 0.10.6.1.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
堆缓冲区溢出
Vulnerability Title
neutrinolabs xrdp 缓冲区错误漏洞
Vulnerability Description
neutrinolabs xrdp是neutrinolabs团队开源的一款开源远程桌面协议服务器。 neutrinolabs xrdp 0.10.6及之前版本存在缓冲区错误漏洞,该漏洞源于虚拟通道转发机制中使用的固定大小缓冲区对传入有效载荷缺乏充分的边界检查,可能导致经过身份验证的远程攻击者发送特制的虚拟通道消息导致堆内存损坏,从而导致拒绝服务或执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A