You are here
Home > Preporuke > Sigurnosni nedostatak programskog paketa xrdp

Sigurnosni nedostatak programskog paketa xrdp

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LFE

——————————————————————————–
Fedora Update Notification
FEDORA-2017-4603342f9a
2018-01-09 15:17:15.722108
——————————————————————————–

Name : xrdp
Product : Fedora 26
Version : 0.9.5
Release : 1.fc26
URL : http://www.xrdp.org/
Summary : Open source remote desktop protocol (RDP) server
Description :
xrdp provides a fully functional RDP server compatible with a wide range
of RDP clients, including FreeRDP and Microsoft RDP client.

——————————————————————————–
Update Information:

Security fixes – Fix local denial of service CVE-2017-16927 #958 #979 (fix
already in 0.9.4-2) New features – Add a new log level TRACE more verbose than
DEBUG #835 #944 – SSH agent forwarding via RDP #867 #868 FreeRDP/FreeRDP#4122 –
Support horizontal wheel properly #928 Bug fixes – Avoid use of hard-coded
sesman port #895 – Workaround for corrupted display with Windows Server 2008
using NeutrinoRDP #869 – Fix glitch in audio redirection by AAC #910 #936 –
Implement vsock support #930 #935 #948 – Avoid 100% CPU usage on SSL accept #956
Other changes – Add US Dvorak keyboard #929 – Suppress some misleading logs
#964 – Add Finnish keyboard #972 – Add more user-friendlier description about
Xorg config #974 – Renew pulseaudio document #984 #985 – Lots of cleanups and
refactoring Known issues – Audio redirection by MP3 codec doesn’t sound with
some client, use AAC instead #965
——————————————————————————–
References:

[ 1 ] Bug #1516760 – CVE-2017-16927 xrdp: Buffer-overflow in scp_v0s_accept function in session manager [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1516760
——————————————————————————–

This update can be installed with the “dnf” update program. Use
su -c ‘dnf upgrade xrdp’ at the command line.
For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list — package-announce@lists.fedoraproject.org
To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

——————————————————————————–
Fedora Update Notification
FEDORA-2017-1c73749b66
2018-01-09 23:48:23.443337
——————————————————————————–

Name : xrdp
Product : Fedora 27
Version : 0.9.5
Release : 1.fc27
URL : http://www.xrdp.org/
Summary : Open source remote desktop protocol (RDP) server
Description :
xrdp provides a fully functional RDP server compatible with a wide range
of RDP clients, including FreeRDP and Microsoft RDP client.

——————————————————————————–
Update Information:

Security fixes – Fix local denial of service CVE-2017-16927 #958 #979 (fix
already in 0.9.4-2) New features – Add a new log level TRACE more verbose than
DEBUG #835 #944 – SSH agent forwarding via RDP #867 #868 FreeRDP/FreeRDP#4122 –
Support horizontal wheel properly #928 Bug fixes – Avoid use of hard-coded
sesman port #895 – Workaround for corrupted display with Windows Server 2008
using NeutrinoRDP #869 – Fix glitch in audio redirection by AAC #910 #936 –
Implement vsock support #930 #935 #948 – Avoid 100% CPU usage on SSL accept #956
Other changes – Add US Dvorak keyboard #929 – Suppress some misleading logs
#964 – Add Finnish keyboard #972 – Add more user-friendlier description about
Xorg config #974 – Renew pulseaudio document #984 #985 – Lots of cleanups and
refactoring Known issues – Audio redirection by MP3 codec doesn’t sound with
some client, use AAC instead #965
——————————————————————————–
References:

[ 1 ] Bug #1516760 – CVE-2017-16927 xrdp: Buffer-overflow in scp_v0s_accept function in session manager [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1516760
——————————————————————————–

This update can be installed with the “dnf” update program. Use
su -c ‘dnf upgrade xrdp’ at the command line.
For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list — package-announce@lists.fedoraproject.org
To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

AutorDanijel Kozinovic
Cert idNCERT-REF-2018-01-0045-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
Izvorhttp://www.adobe.com/
Top
More in Preporuke
Sigurnosni nedostaci programskog paketa java-1_7_0-openjdk

Otkriveni su sigurnosni nedostaci u programskom paketu java-1_7_0-openjdk za operacijski sustav openSUSE. Otkriveni nedostaci potencijalnim napadačima omogućuju izazivanje DoS stanja,...

Close