7.5
CVSSv2

CVE-2008-5903

Published: 15/01/2009 Updated: 08/08/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Array index error in the xrdp_bitmap_def_proc function in xrdp/funcs.c in xrdp 0.4.1 and previous versions allows remote malicious users to execute arbitrary code via vectors that manipulate the value of the edit_pos structure member.

Vulnerable Product Search on Vulmon Subscribe to Product

xrdp xrdp 0.3.2

xrdp xrdp 0.3.1

xrdp xrdp 0.3

xrdp xrdp

xrdp xrdp 0.4

Vendor Advisories

Debian Bug report logs - #511641 xrdp: CVE-2008-590[2-4] arbitrary code execution Package: xrdp; Maintainer for xrdp is Debian Remote Maintainers <debian-remote@listsdebianorg>; Source for xrdp is src:xrdp (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Tue, 13 Jan 2009 00:03:02 UTC Se ...