Bug 30063 - xrdp new security issue CVE-2022-23613
Summary: xrdp new security issue CVE-2022-23613
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: Cauldron
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: All Packagers
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2022-02-17 19:06 CET by David Walser
Modified: 2022-02-18 17:57 CET (History)
1 user (show)

See Also:
Source RPM: xrdp-0.9.17-1.mga9.src.rpm
CVE:
Status comment: Patch available from Fedora


Attachments

Description David Walser 2022-02-17 19:06:39 CET
Fedora has issued an advisory today (February 17):
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/K5ONRGARKHGFU2CIEQ7E6M6VJZEM5XWW/

Mageia 8 is also affected.
David Walser 2022-02-17 19:07:01 CET

Whiteboard: (none) => MGA8TOO
Status comment: (none) => Patch available from Fedora

Comment 1 Lewis Smith 2022-02-17 21:36:04 CET
I hesitate to do this, but luigi is the noted maintainer of this package, and does things on it, so assigning this to you, exceptionally. If this is wrong, re-assign it as you see fit: pkg-bugs?

Assignee: bugsquad => luigiwalser

David Walser 2022-02-17 22:24:26 CET

Assignee: luigiwalser => pkg-bugs

Comment 2 Nicolas Salguero 2022-02-18 09:50:21 CET
Hi,

For Cauldron, xrdp-0.9.18.1-1.mga9 solves the issue.

I did not find the offending code for Mageia 8 (version 0.9.15) and it is confirmed by Debian which says the issue was introduced in version 0.9.17.

Best regards,

Nico.

CC: (none) => nicolas.salguero

Comment 3 David Walser 2022-02-18 17:57:46 CET
Thanks!

Resolution: (none) => FIXED
Whiteboard: MGA8TOO => (none)
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.