Oval Definition:oval:org.opensuse.security:def:58134
Revision Date:2020-12-01Version:1
Title:Security update for xrdp (Important)
Description:

This update for xrdp fixes the following issues:

Security issues fixed:

- CVE-2013-1430: When successfully logging in using RDP into an xrdp session, the file ~/.vnc/sesman_${username}_passwd was created. Its content was the equivalent of the user's cleartext password, DES encrypted with a known key (bsc#1015567). - CVE-2017-16927: The scp_v0s_accept function in sesman/libscp/libscp_v0.c in the session manager in xrdp through used an untrusted integer as a write length, which could lead to a local denial of service (bsc#1069591). - CVE-2017-6967: Fixed call of the PAM function auth_start_session(). This lead to to PAM session modules not being properly initialized, with a potential consequence of incorrect configurations or elevation of privileges, aka a pam_limits.so bypass (bsc#1029912).

Other issues addressed:

- The KillDisconnected option for TigerVNC Xvnc sessions is now supported (bsc#1101506) - Fixed an issue with delayed X KeyRelease events (bsc#1100453) - Force xrdp-sesman.service to start after xrdp.service. (bsc#1014524) - Avoid use of hard-coded sesman port. (bsc#1060644) - Backport upstream commit 5575197, sesman should stop setting LANG and let initialization scripts take care of it (bsc#1023988). - Backport upstream patches for 32bpp support (bsc#1022098). - Fixed a regression connecting from Windows 10. (bsc#1090174)
Family:unixClass:patch
Status:Reference(s):1000998
1009434
1010399
1010405
1010406
1010408
1010409
1010421
1010423
1010424
1010425
1010426
1011377
1011390
1011395
1011398
1011404
1011406
1011411
1011417
1014524
1015567
1022098
1023988
1025108
1027519
1029912
1040543
1041447
1041470
1043008
1047281
1060644
1061310
1069591
1074235
1074562
1085449
1086039
1086598
1087481
1090174
1092611
1092631
1093311
1100453
1101506
1106119
1114459
1120374
1123823
1123828
1123832
1126463
1129231
1131060
1137990
1149429
1154738
1157763
1160968
1164860
1172031
1172225
1174117
1176756
1177872
943216
956365
959933
981252
983922
988028
992038
992606
CVE-2013-1430
CVE-2015-5219
CVE-2016-2830
CVE-2016-5289
CVE-2016-5292
CVE-2016-7426
CVE-2016-7427
CVE-2016-7428
CVE-2016-7429
CVE-2016-7431
CVE-2016-7433
CVE-2016-7434
CVE-2016-7545
CVE-2016-9063
CVE-2016-9067
CVE-2016-9068
CVE-2016-9069
CVE-2016-9071
CVE-2016-9073
CVE-2016-9075
CVE-2016-9076
CVE-2016-9077
CVE-2016-9310
CVE-2016-9311
CVE-2017-14970
CVE-2017-16927
CVE-2017-5715
CVE-2017-5753
CVE-2017-5754
CVE-2017-6967
CVE-2017-7789
CVE-2017-9214
CVE-2017-9263
CVE-2017-9265
CVE-2018-1417
CVE-2018-20748
CVE-2018-20749
CVE-2018-20750
CVE-2018-2783
CVE-2018-2790
CVE-2018-2794
CVE-2018-2795
CVE-2018-2796
CVE-2018-2797
CVE-2018-2798
CVE-2018-2799
CVE-2018-2800
CVE-2018-2814
CVE-2018-2825
CVE-2018-2826
CVE-2018-3639
CVE-2018-3741
CVE-2018-5150
CVE-2018-5151
CVE-2018-5152
CVE-2018-5153
CVE-2018-5154
CVE-2018-5155
CVE-2018-5157
CVE-2018-5158
CVE-2018-5159
CVE-2018-5160
CVE-2018-5163
CVE-2018-5164
CVE-2018-5165
CVE-2018-5166
CVE-2018-5167
CVE-2018-5168
CVE-2018-5169
CVE-2018-5172
CVE-2018-5173
CVE-2018-5174
CVE-2018-5175
CVE-2018-5176
CVE-2018-5177
CVE-2018-5178
CVE-2018-5179
CVE-2018-5180
CVE-2018-5181
CVE-2018-5182
CVE-2018-5183
CVE-2019-11757
CVE-2019-11758
CVE-2019-11759
CVE-2019-11760
CVE-2019-11761
CVE-2019-11762
CVE-2019-11763
CVE-2019-11764
CVE-2019-15903
CVE-2019-15961
CVE-2019-20807
CVE-2019-3880
CVE-2020-13935
CVE-2020-15683
CVE-2020-15969
CVE-2020-1935
CVE-2020-2583
CVE-2020-2590
CVE-2020-2593
CVE-2020-2601
CVE-2020-2604
CVE-2020-2654
CVE-2020-2659
SUSE-SU-2016:3195-1
SUSE-SU-2017:0338-1
SUSE-SU-2018:0311-1
SUSE-SU-2019:0313-1
SUSE-SU-2019:0736-1
SUSE-SU-2019:1203-1
SUSE-SU-2019:1860-1
SUSE-SU-2019:2182-1
SUSE-SU-2019:2872-1
SUSE-SU-2019:3177-1
SUSE-SU-2020:0628-1
SUSE-SU-2020:1550-1
SUSE-SU-2020:2611-1
SUSE-SU-2020:3053-1
Platform(s):openSUSE Leap 15.0
openSUSE Leap 15.1
SUSE Linux Enterprise Server 12 SP2
SUSE Linux Enterprise Server 12 SP2-BCL
SUSE Linux Enterprise Server 12 SP2-ESPOS
SUSE Linux Enterprise Server 12 SP2-LTSS
SUSE Linux Enterprise Server 12 SP3
SUSE Linux Enterprise Server 12 SP3-BCL
SUSE Linux Enterprise Server 12 SP3-ESPOS
SUSE Linux Enterprise Server 12 SP3-LTSS
SUSE Linux Enterprise Server 12 SP3-TERADATA
SUSE Linux Enterprise Server 12 SP4
SUSE OpenStack Cloud 7
SUSE OpenStack Cloud 8
SUSE OpenStack Cloud Crowbar 8
Product(s):
Definition Synopsis
  • openSUSE Leap 15.0 is installed
  • AND Package Information
  • libsox3-14.4.2-lp150.3 is installed
  • OR sox-14.4.2-lp150.3 is installed
  • Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND Package Information
  • python-reportlab-3.4.0-lp151.3.3 is installed
  • OR python2-reportlab-3.4.0-lp151.3.3 is installed
  • OR python3-reportlab-3.4.0-lp151.3.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2 is installed
  • AND Package Information
  • ntp-4.2.8p9-55 is installed
  • OR ntp-doc-4.2.8p9-55 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-BCL is installed
  • AND Package Information
  • LibVNCServer-0.9.9-17.11 is installed
  • OR libvncclient0-0.9.9-17.11 is installed
  • OR libvncserver0-0.9.9-17.11 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-ESPOS is installed
  • AND Package Information
  • xen-4.7.5_04-43.33 is installed
  • OR xen-doc-html-4.7.5_04-43.33 is installed
  • OR xen-libs-4.7.5_04-43.33 is installed
  • OR xen-libs-32bit-4.7.5_04-43.33 is installed
  • OR xen-tools-4.7.5_04-43.33 is installed
  • OR xen-tools-domU-4.7.5_04-43.33 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-LTSS is installed
  • AND Package Information
  • libdcerpc-binding0-4.4.2-38.25 is installed
  • OR libdcerpc-binding0-32bit-4.4.2-38.25 is installed
  • OR libdcerpc0-4.4.2-38.25 is installed
  • OR libdcerpc0-32bit-4.4.2-38.25 is installed
  • OR libndr-krb5pac0-4.4.2-38.25 is installed
  • OR libndr-krb5pac0-32bit-4.4.2-38.25 is installed
  • OR libndr-nbt0-4.4.2-38.25 is installed
  • OR libndr-nbt0-32bit-4.4.2-38.25 is installed
  • OR libndr-standard0-4.4.2-38.25 is installed
  • OR libndr-standard0-32bit-4.4.2-38.25 is installed
  • OR libndr0-4.4.2-38.25 is installed
  • OR libndr0-32bit-4.4.2-38.25 is installed
  • OR libnetapi0-4.4.2-38.25 is installed
  • OR libnetapi0-32bit-4.4.2-38.25 is installed
  • OR libsamba-credentials0-4.4.2-38.25 is installed
  • OR libsamba-credentials0-32bit-4.4.2-38.25 is installed
  • OR libsamba-errors0-4.4.2-38.25 is installed
  • OR libsamba-errors0-32bit-4.4.2-38.25 is installed
  • OR libsamba-hostconfig0-4.4.2-38.25 is installed
  • OR libsamba-hostconfig0-32bit-4.4.2-38.25 is installed
  • OR libsamba-passdb0-4.4.2-38.25 is installed
  • OR libsamba-passdb0-32bit-4.4.2-38.25 is installed
  • OR libsamba-util0-4.4.2-38.25 is installed
  • OR libsamba-util0-32bit-4.4.2-38.25 is installed
  • OR libsamdb0-4.4.2-38.25 is installed
  • OR libsamdb0-32bit-4.4.2-38.25 is installed
  • OR libsmbclient0-4.4.2-38.25 is installed
  • OR libsmbclient0-32bit-4.4.2-38.25 is installed
  • OR libsmbconf0-4.4.2-38.25 is installed
  • OR libsmbconf0-32bit-4.4.2-38.25 is installed
  • OR libsmbldap0-4.4.2-38.25 is installed
  • OR libsmbldap0-32bit-4.4.2-38.25 is installed
  • OR libtevent-util0-4.4.2-38.25 is installed
  • OR libtevent-util0-32bit-4.4.2-38.25 is installed
  • OR libwbclient0-4.4.2-38.25 is installed
  • OR libwbclient0-32bit-4.4.2-38.25 is installed
  • OR samba-4.4.2-38.25 is installed
  • OR samba-client-4.4.2-38.25 is installed
  • OR samba-client-32bit-4.4.2-38.25 is installed
  • OR samba-doc-4.4.2-38.25 is installed
  • OR samba-libs-4.4.2-38.25 is installed
  • OR samba-libs-32bit-4.4.2-38.25 is installed
  • OR samba-winbind-4.4.2-38.25 is installed
  • OR samba-winbind-32bit-4.4.2-38.25 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3 is installed
  • AND Package Information
  • bind-9.9.9P1-62 is installed
  • OR bind-chrootenv-9.9.9P1-62 is installed
  • OR bind-doc-9.9.9P1-62 is installed
  • OR bind-libs-9.9.9P1-62 is installed
  • OR bind-libs-32bit-9.9.9P1-62 is installed
  • OR bind-utils-9.9.9P1-62 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-BCL is installed
  • AND Package Information
  • perl-5.18.2-12.20 is installed
  • OR perl-32bit-5.18.2-12.20 is installed
  • OR perl-base-5.18.2-12.20 is installed
  • OR perl-doc-5.18.2-12.20 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-ESPOS is installed
  • AND gdb-8.3.1-2.14 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-LTSS is installed
  • AND Package Information
  • libpolkit0-0.113-5.18 is installed
  • OR polkit-0.113-5.18 is installed
  • OR typelib-1_0-Polkit-1_0-0.113-5.18 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-TERADATA is installed
  • AND Package Information
  • NetworkManager-1.0.12-13.12 is installed
  • OR libnm-glib-vpn1-1.0.12-13.12 is installed
  • OR libnm-glib4-1.0.12-13.12 is installed
  • OR libnm-util2-1.0.12-13.12 is installed
  • OR libnm0-1.0.12-13.12 is installed
  • OR typelib-1_0-NMClient-1_0-1.0.12-13.12 is installed
  • OR typelib-1_0-NetworkManager-1_0-1.0.12-13.12 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND Package Information
  • avahi-0.6.32-30 is installed
  • OR avahi-lang-0.6.32-30 is installed
  • OR avahi-utils-0.6.32-30 is installed
  • OR libavahi-client3-0.6.32-30 is installed
  • OR libavahi-client3-32bit-0.6.32-30 is installed
  • OR libavahi-common3-0.6.32-30 is installed
  • OR libavahi-common3-32bit-0.6.32-30 is installed
  • OR libavahi-core7-0.6.32-30 is installed
  • OR libdns_sd-0.6.32-30 is installed
  • OR libdns_sd-32bit-0.6.32-30 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 7 is installed
  • AND xrdp-0.9.0~git.1456906198.f422461-16.9 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 8 is installed
  • AND Package Information
  • ghostscript-9.27-23.31 is installed
  • OR ghostscript-x11-9.27-23.31 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud Crowbar 8 is installed
  • AND Package Information
  • libmysqlclient18-10.0.38-29.27 is installed
  • OR mariadb-10.0.38-29.27 is installed
  • BACK