Bug 2433417 (CVE-2025-68670)
| Summary: | CVE-2025-68670 xrdp: xrdp: Remote code execution via unauthenticated stack-based buffer overflow | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | urgent | Docs Contact: | |
| Priority: | urgent | ||
| Version: | unspecified | CC: | fedora |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in xrdp. This unauthenticated stack-based buffer overflow vulnerability allows remote attackers to execute arbitrary code on the target system. The issue arises from improper bounds checking when processing user domain information during the connection sequence, which can lead to overwriting the stack buffer and redirecting execution flow. This could enable an attacker to gain full control over the affected system.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2433438, 2433439, 2433440, 2433441, 2433442 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-01-27 16:04:50 UTC
Should be fixed in 500f161a308d1535ef3d58dc6b6a34646392f048 |