Advisories ยป MGASA-2017-0456

Updated xrdp packages fix security vulnerability

Publication date: 21 Dec 2017
Modification date: 21 Dec 2017
Type: security
Affected Mageia releases : 6
CVE: CVE-2017-16927

Description

The scp_v0s_accept function in sesman/libscp/libscp_v0.c in the session
manager in xrdp through 0.9.4 uses an untrusted integer as a write
length, which allows local users to cause a denial of service (buffer
overflow and application crash) or possibly have unspecified other
impact via a crafted input stream. (CVE-2017-16927)
                

References

SRPMS

6/core