{"affected":[{"ecosystem_specific":{"binaries":[{"xrdp":"0.9.0~git.1456906198.f422461-16.9.3"}]},"package":{"ecosystem":"SUSE:OpenStack Cloud 7","name":"xrdp","purl":"pkg:rpm/suse/xrdp&distro=SUSE%20OpenStack%20Cloud%207"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"0.9.0~git.1456906198.f422461-16.9.3"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"xrdp":"0.9.0~git.1456906198.f422461-16.9.3"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12 SP2","name":"xrdp","purl":"pkg:rpm/suse/xrdp&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"0.9.0~git.1456906198.f422461-16.9.3"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"xrdp":"0.9.0~git.1456906198.f422461-16.9.3"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 12 SP2-LTSS","name":"xrdp","purl":"pkg:rpm/suse/xrdp&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-LTSS"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"0.9.0~git.1456906198.f422461-16.9.3"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"xrdp":"0.9.0~git.1456906198.f422461-16.9.3"}]},"package":{"ecosystem":"SUSE:Enterprise Storage 4","name":"xrdp","purl":"pkg:rpm/suse/xrdp&distro=SUSE%20Enterprise%20Storage%204"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"0.9.0~git.1456906198.f422461-16.9.3"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"This update for xrdp fixes the following issues:\n\nSecurity issues fixed: \n\n- CVE-2013-1430:  When successfully logging in using RDP into an xrdp session,\n  the file ~/.vnc/sesman_${username}_passwd was created. Its content was the equivalent\n  of the user's cleartext password, DES encrypted with a known key (bsc#1015567).\n- CVE-2017-16927: The scp_v0s_accept function in sesman/libscp/libscp_v0.c in the session manager\n  in xrdp through used an untrusted integer as a write length, which could lead to a\n  local denial of service (bsc#1069591).\n- CVE-2017-6967: Fixed call of the PAM function auth_start_session(). This lead\n  to to PAM session modules not being properly initialized, with a potential\n  consequence of incorrect configurations or elevation of privileges, aka a\n  pam_limits.so bypass (bsc#1029912).\n\nOther issues addressed:\n\n- The KillDisconnected option for TigerVNC Xvnc sessions is now supported (bsc#1101506)\n- Fixed an issue with delayed X KeyRelease events (bsc#1100453)\n- Force xrdp-sesman.service to start after xrdp.service. (bsc#1014524)\n- Avoid use of hard-coded sesman port. (bsc#1060644)\n- Backport upstream commit 5575197,\n  sesman should stop setting LANG and let initialization scripts\n  take care of it (bsc#1023988).\n- Backport upstream patches for 32bpp support (bsc#1022098).\n- Fixed a regression connecting from Windows 10. (bsc#1090174)\n","id":"SUSE-SU-2019:1860-1","modified":"2019-07-16T13:30:46Z","published":"2019-07-16T13:30:46Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2019/suse-su-20191860-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1014524"},{"type":"REPORT","url":"https://bugzilla.suse.com/1015567"},{"type":"REPORT","url":"https://bugzilla.suse.com/1022098"},{"type":"REPORT","url":"https://bugzilla.suse.com/1023988"},{"type":"REPORT","url":"https://bugzilla.suse.com/1029912"},{"type":"REPORT","url":"https://bugzilla.suse.com/1060644"},{"type":"REPORT","url":"https://bugzilla.suse.com/1069591"},{"type":"REPORT","url":"https://bugzilla.suse.com/1090174"},{"type":"REPORT","url":"https://bugzilla.suse.com/1100453"},{"type":"REPORT","url":"https://bugzilla.suse.com/1101506"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2013-1430"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-16927"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-6967"}],"related":["CVE-2013-1430","CVE-2017-16927","CVE-2017-6967"],"summary":"Security update for xrdp","upstream":["CVE-2013-1430","CVE-2017-16927","CVE-2017-6967"]}