Oval Definition:oval:org.opensuse.security:def:63732
Revision Date:2020-12-01Version:1
Title:Security update for xrdp (Important)
Description:

This update for xrdp fixes the following issues:

These security issues were fixed:

- CVE-2013-1430: When successfully logging in using RDP into an xrdp session, the file ~/.vnc/sesman_${username}_passwd was created. Its content was the equivalent of the user's cleartext password, DES encrypted with a known key (bsc#1015567). - CVE-2017-16927: The scp_v0s_accept function in sesman/libscp/libscp_v0.c in the session manager in xrdp through used an untrusted integer as a write length, which could lead to a local denial of service (bsc#1069591). - CVE-2017-6967: Fixed call of the PAM function auth_start_session(). This lead to to PAM session modules not being properly initialized, with a potential consequence of incorrect configurations or elevation of privileges, aka a pam_limits.so bypass (bsc#1029912).

These non-security issues were fixed:

- The KillDisconnected option for TigerVNC Xvnc sessions is now supported (bsc#1101506) - Fixed an issue with delayed X KeyRelease events (bsc#1100453) - Force xrdp-sesman.service to start after xrdp.service. (bsc#1014524) - Avoid use of hard-coded sesman port. (bsc#1060644) - Fixed a regression connecting from Windows 10. (bsc#1090174)
Family:unixClass:patch
Status:Reference(s):1013712
1014524
1015567
1029912
1050241
1060644
1069591
1090174
1096894
1100453
1101506
1118301
1118346
1118348
1118349
1118351
1119789
1121943
1121944
1121945
1127820
1127821
1127822
1133200
1133201
1140120
1141670
1152987
1160903
1160905
1163933
1165471
1174117
1174121
1174538
990204
CVE-2013-1430
CVE-2015-9542
CVE-2016-9798
CVE-2017-16927
CVE-2017-6967
CVE-2017-7890
CVE-2018-11499
CVE-2018-12178
CVE-2018-12180
CVE-2018-14553
CVE-2018-19797
CVE-2018-19827
CVE-2018-19837
CVE-2018-19838
CVE-2018-19839
CVE-2018-20190
CVE-2018-20821
CVE-2018-20822
CVE-2018-3630
CVE-2019-11038
CVE-2019-16328
CVE-2019-18902
CVE-2019-6283
CVE-2019-6284
CVE-2019-6286
CVE-2020-13934
CVE-2020-13935
CVE-2020-15652
CVE-2020-15659
CVE-2020-6463
CVE-2020-6514
CVE-2020-7216
openSUSE-SU-2019:1791-1
openSUSE-SU-2020:0165-1
openSUSE-SU-2020:0685-1
openSUSE-SU-2020:1205-1
SUSE-SU-2019:0581-1
SUSE-SU-2019:1847-1
SUSE-SU-2019:2258-1
SUSE-SU-2019:2915-1
SUSE-SU-2020:0623-1
SUSE-SU-2020:1117-1
SUSE-SU-2020:2037-1
Platform(s):openSUSE Leap 15.1
openSUSE Leap 15.2
SUSE Linux Enterprise Server 12 SP4
SUSE Linux Enterprise Server 12 SP4-LTSS
Product(s):
Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND Package Information
  • libsass-3.6.1-lp151.3.3 is installed
  • OR libsass-3_6_1-1-3.6.1-lp151.3.3 is installed
  • OR libsass-devel-3.6.1-lp151.3.3 is installed
  • Definition Synopsis
  • openSUSE Leap 15.2 is installed
  • AND Package Information
  • MozillaThunderbird-68.11.0-lp152.2.7 is installed
  • OR MozillaThunderbird-translations-common-68.11.0-lp152.2.7 is installed
  • OR MozillaThunderbird-translations-other-68.11.0-lp152.2.7 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND xrdp-0.9.0~git.1456906198.f422461-21.9 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4-LTSS is installed
  • AND Package Information
  • tomcat-9.0.36-3.45 is installed
  • OR tomcat-admin-webapps-9.0.36-3.45 is installed
  • OR tomcat-docs-webapp-9.0.36-3.45 is installed
  • OR tomcat-el-3_0-api-9.0.36-3.45 is installed
  • OR tomcat-javadoc-9.0.36-3.45 is installed
  • OR tomcat-jsp-2_3-api-9.0.36-3.45 is installed
  • OR tomcat-lib-9.0.36-3.45 is installed
  • OR tomcat-servlet-4_0-api-9.0.36-3.45 is installed
  • OR tomcat-webapps-9.0.36-3.45 is installed
  • BACK