Bug 1215803 (CVE-2023-42822) - VUL-0: CVE-2023-42822: xrdp: unchecked access to font glyph info
Summary: VUL-0: CVE-2023-42822: xrdp: unchecked access to font glyph info
Status: NEW
Alias: CVE-2023-42822
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/380173/
Whiteboard: CVSSv3.1:SUSE:CVE-2023-42822:4.6:(AV:...
Keywords:
Depends on:
Blocks:
 
Reported: 2023-09-28 10:10 UTC by SMASH SMASH
Modified: 2023-12-14 20:30 UTC (History)
4 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description SMASH SMASH 2023-09-28 10:10:43 UTC
xrdp is an open source remote desktop protocol server. Access to the font
glyphs in xrdp_painter.c is not bounds-checked . Since some of this data is
controllable by the user, this can result in an out-of-bounds read within the
xrdp executable. The vulnerability allows an out-of-bounds read within a
potentially privileged process. On non-Debian platforms, xrdp tends to run as
root. Potentially an out-of-bounds write can follow the out-of-bounds read.
There is no denial-of-service impact, providing xrdp is running in forking mode.
This issue has been addressed in release 0.9.23.1. Users are advised to upgrade.
There are no known workarounds for this vulnerability.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-42822
Comment 6 Maintenance Automation 2023-11-27 12:30:31 UTC
SUSE-SU-2023:4577-1: An update that solves one vulnerability can now be installed.

Category: security (moderate)
Bug References: 1215803
CVE References: CVE-2023-42822
Sources used:
openSUSE Leap 15.4 (src): xrdp-0.9.13.1-150200.4.27.1
openSUSE Leap 15.5 (src): xrdp-0.9.13.1-150200.4.27.1
Basesystem Module 15-SP4 (src): xrdp-0.9.13.1-150200.4.27.1
Basesystem Module 15-SP5 (src): xrdp-0.9.13.1-150200.4.27.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 8 Maintenance Automation 2023-12-14 20:30:17 UTC
SUSE-SU-2023:4873-1: An update that solves two vulnerabilities and has one security fix can now be installed.

Category: security (moderate)
Bug References: 1214805, 1215803, 1217759
CVE References: CVE-2023-40184, CVE-2023-42822
Sources used:
SUSE Linux Enterprise High Performance Computing 12 SP5 (src): xrdp-0.9.10-3.16.1
SUSE Linux Enterprise Server 12 SP5 (src): xrdp-0.9.10-3.16.1
SUSE Linux Enterprise Server for SAP Applications 12 SP5 (src): xrdp-0.9.10-3.16.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.