Bug 20518 - xrdp new security issue CVE-2017-6967
Summary: xrdp new security issue CVE-2017-6967
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: Cauldron
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: David Walser
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2017-03-18 23:49 CET by David Walser
Modified: 2017-04-26 02:07 CEST (History)
2 users (show)

See Also:
Source RPM: xrdp-0.9.1-1.mga6.src.rpm
CVE: CVE-2017-6967
Status comment:


Attachments

Description David Walser 2017-03-18 23:49:40 CET
A security issue in xrdp has been announced on March 17:
http://openwall.com/lists/oss-security/2017/03/18/1

They link to a proposed fix, but it's not committed upstream and doesn't quite apply to the current version (the first two files' changes do, but the third doesn't).
Comment 1 Marja Van Waes 2017-03-19 17:24:05 CET
Assigning to the registered maintainer.

CC: (none) => marja11
Assignee: bugsquad => luigiwalser

Nicolas Lécureuil 2017-04-25 15:06:24 CEST

CC: (none) => mageia
CVE: (none) => CVE-2017-6967

Comment 2 Nicolas Lécureuil 2017-04-25 15:30:55 CEST
fixed on cauldron.

Status: NEW => RESOLVED
Resolution: (none) => FIXED

Comment 3 David Walser 2017-04-26 02:07:57 CEST
Thanks.  It still needs to be resynced with Fedora too.

Note You need to log in before you can comment on or make changes to this bug.