SUSE-SR:2009:003Vendor advisory
http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00000.html CVE-2008-5904
XRDP 0.4.1 - Remote Buffer Overflow (PoC)
Record summary
CVE-2008-5904 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
The rdp_rdp_process_color_pointer_pdu function in rdp/rdp_rdp.c in xrdp 0.4.1 and earlier allows remote RDP servers to have an unknown impact via input data that sets crafted values for certain length variables, leading to a buffer overflow.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBXRDP 0.4.1 - Remote Buffer Overflow (PoC)ExploitDB exploitby joe walkoNot analyzed1 file
References
5[oss-security] 20090112 CVE request: xrdpmailing list
http://openwall.com/lists/oss-security/2009/01/12/3 packetstormsecurity.org
http://packetstormsecurity.org/0812-advisories/VA_VD_87_08_XRDP.pdf xrdp-rdprdpprocesscolorpointerpdu-bo(48094)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/48094 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2008-5904