{"affected":[{"ecosystem_specific":{"binaries":[{"xrdp":"0.9.0~git.1456906198.f422461-21.9.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Desktop 12 SP4","name":"xrdp","purl":"pkg:rpm/suse/xrdp&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP4"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"0.9.0~git.1456906198.f422461-21.9.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"xrdp":"0.9.0~git.1456906198.f422461-21.9.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 12 SP4","name":"xrdp","purl":"pkg:rpm/suse/xrdp&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"0.9.0~git.1456906198.f422461-21.9.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"xrdp":"0.9.0~git.1456906198.f422461-21.9.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12 SP4","name":"xrdp","purl":"pkg:rpm/suse/xrdp&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"0.9.0~git.1456906198.f422461-21.9.1"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"This update for xrdp fixes the following issues:\n\nThese security issues were fixed:\n\n- CVE-2013-1430:  When successfully logging in using RDP into an xrdp session, \n  the file ~/.vnc/sesman_${username}_passwd was created. Its content was the equivalent \n  of the user's cleartext password, DES encrypted with a known key (bsc#1015567).\n- CVE-2017-16927: The scp_v0s_accept function in sesman/libscp/libscp_v0.c in the session manager \n  in xrdp through used an untrusted integer as a write length, which could lead to a \n  local denial of service (bsc#1069591).\n- CVE-2017-6967: Fixed call of the PAM function auth_start_session(). This lead\n  to to PAM session modules not being properly initialized, with a potential\n  consequence of incorrect configurations or elevation of privileges, aka a\n  pam_limits.so bypass (bsc#1029912).\n\nThese non-security issues were fixed:\n\n- The KillDisconnected option for TigerVNC Xvnc sessions is now supported (bsc#1101506)\n- Fixed an issue with delayed X KeyRelease events (bsc#1100453)    \n- Force xrdp-sesman.service to start after xrdp.service. (bsc#1014524)\n- Avoid use of hard-coded sesman port. (bsc#1060644)\n- Fixed a regression connecting from Windows 10. (bsc#1090174)\n","id":"SUSE-SU-2019:1847-1","modified":"2019-07-15T12:38:52Z","published":"2019-07-15T12:38:52Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2019/suse-su-20191847-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1014524"},{"type":"REPORT","url":"https://bugzilla.suse.com/1015567"},{"type":"REPORT","url":"https://bugzilla.suse.com/1029912"},{"type":"REPORT","url":"https://bugzilla.suse.com/1060644"},{"type":"REPORT","url":"https://bugzilla.suse.com/1069591"},{"type":"REPORT","url":"https://bugzilla.suse.com/1090174"},{"type":"REPORT","url":"https://bugzilla.suse.com/1100453"},{"type":"REPORT","url":"https://bugzilla.suse.com/1101506"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2013-1430"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-16927"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-6967"}],"related":["CVE-2013-1430","CVE-2017-16927","CVE-2017-6967"],"summary":"Security update for xrdp","upstream":["CVE-2013-1430","CVE-2017-16927","CVE-2017-6967"]}