7.5
CVSSv2

CVE-2008-5904

Published: 15/01/2009 Updated: 08/08/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The rdp_rdp_process_color_pointer_pdu function in rdp/rdp_rdp.c in xrdp 0.4.1 and previous versions allows remote RDP servers to have an unknown impact via input data that sets crafted values for certain length variables, leading to a buffer overflow.

Vulnerable Product Search on Vulmon Subscribe to Product

xrdp xrdp 0.3

xrdp xrdp 0.3.2

xrdp xrdp 0.3.1

xrdp xrdp

xrdp xrdp 0.4

Vendor Advisories

Debian Bug report logs - #511641 xrdp: CVE-2008-590[2-4] arbitrary code execution Package: xrdp; Maintainer for xrdp is Debian Remote Maintainers <debian-remote@listsdebianorg>; Source for xrdp is src:xrdp (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Tue, 13 Jan 2009 00:03:02 UTC Se ...

Exploits

/* XRDP <= 041 pre-auth remote PoC exploit (xrdpsourceforgenet) ******************************************************************************** 01:59:56 root@crateria:~/xrdp# gcc -w -lssl -lX11 xrdp-pocc -o xrdp-poc 02:00:29 root@crateria:~/xrdp# /xrdp-poc 100013 [=] Connected to 100013 [=] Hit CTRL-C if the progress bar s ...