Reported by Gilad Kleinman.
An integer underflow leading to a heap overflow in the sesman server allows any unauthenticated attacker which is accessible to a sesman server (listens by default on localhost when installing xrdp, but can be remote if configured otherwise) to execute code as root.
Impact
Root code execution on any sesman server accessible.
Patches
Patched in versions 0.9.18.1 or 0.9.19 and above
Workarounds
None
Reported by Gilad Kleinman.
An integer underflow leading to a heap overflow in the sesman server allows any unauthenticated attacker which is accessible to a sesman server (listens by default on localhost when installing xrdp, but can be remote if configured otherwise) to execute code as root.
Impact
Root code execution on any sesman server accessible.
Patches
Patched in versions 0.9.18.1 or 0.9.19 and above
Workarounds
None