[Secure-testing-team] Bug#511641: xrdp: Multiple security issues

Moritz Muehlenhoff jmm at debian.org
Tue Jan 13 00:02:05 UTC 2009


Package: xrdp
Severity: grave
Tags: security
Justification: user security hole

Several vulnerabilities in xrdp have been spotted on the oss-security
list. Please see this PDF for details:

http://packetstormsecurity.org/0812-advisories/VA_VD_87_08_XRDP.pdf

Cheers,
        Moritz

-- System Information:
Debian Release: 5.0
  APT prefers unstable
  APT policy: (500, 'unstable')
Architecture: i386 (i686)

Kernel: Linux 2.6.26-1-686 (SMP w/1 CPU core)
Locale: LANG=C, LC_CTYPE=de_DE.ISO-8859-15 at euro (charmap=ISO-8859-15)
Shell: /bin/sh linked to /bin/bash

Versions of packages xrdp depends on:
ii  adduser                       3.110      add and remove users and groups
ii  libc6                         2.7-16     GNU C Library: Shared libraries
ii  libpam0g                      1.0.1-4    Pluggable Authentication Modules l
ii  libssl0.9.8                   0.9.8g-14  SSL shared libraries

Versions of packages xrdp recommends:
pn  vnc4server | tightvncserver | <none>     (no description available)

xrdp suggests no packages.





More information about the Secure-testing-team mailing list