{"cves":[{"id":"CVE-2022-44637","published":"2022-12-12T00:00:00","updated_at":"2025-08-26T12:50:06.105689+00:00","description":"\nRedmine before 4.2.9 and 5.0.x before 5.0.4 allows persistent XSS in its\nTextile formatter due to improper sanitization in Redcloth3\nTextile-formatted fields. Depending on the configuration, this may require\nlogin as a registered user.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.redmine.org/projects/redmine/wiki/Security_Advisories","https://www.cve.org/CVERecord?id=CVE-2022-44637"],"bugs":[""],"patches":{"redmine":[]},"tags":{},"packages":[{"name":"redmine","source":"https://ubuntu.com/security/cve?package=redmine","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=redmine","debian":"https://tracker.debian.org/pkg/redmine","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-44031","published":"2022-12-12T00:00:00","updated_at":"2025-08-26T12:49:49.891712+00:00","description":"\nRedmine before 4.2.9 and 5.0.x before 5.0.4 allows persistent XSS in its\nTextile formatter due to improper sanitization of the blockquote syntax in\nTextile-formatted fields.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.redmine.org/projects/redmine/wiki/Security_Advisories","https://www.cve.org/CVERecord?id=CVE-2022-44031"],"bugs":[""],"patches":{"redmine":[]},"tags":{},"packages":[{"name":"redmine","source":"https://ubuntu.com/security/cve?package=redmine","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=redmine","debian":"https://tracker.debian.org/pkg/redmine","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-4399","published":"2022-12-10T22:15:00","updated_at":"2025-08-26T12:49:49.891712+00:00","description":"\nA vulnerability was found in TicklishHoneyBee nodau. It has been rated as\ncritical. Affected by this issue is some unknown functionality of the file\nsrc/db.c. The manipulation of the argument value/name leads to sql\ninjection. The name of the patch is\n7a7d737a3929f335b9717ddbd31db91151b69ad2. It is recommended to apply a\npatch to fix this issue. The identifier of this vulnerability is\nVDB-215252.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","attackVector":"ADJACENT","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/TicklishHoneyBee/nodau/pull/26","https://www.cve.org/CVERecord?id=CVE-2022-4399"],"bugs":[""],"patches":{"nodau":["upsteam: https://github.com/TicklishHoneyBee/nodau/commit/7a7d737a3929f335b9717ddbd31db91151b69ad2"]},"tags":{},"packages":[{"name":"nodau","source":"https://ubuntu.com/security/cve?package=nodau","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=nodau","debian":"https://tracker.debian.org/pkg/nodau","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.3.8-5","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"0.3.8-6","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"0.3.8-6","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"0.3.8-6","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"0.3.8-6","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"0.3.8-6","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"0.3.8-6","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-4398","published":"2022-12-10T20:15:00","updated_at":"2025-07-11T07:53:16.066939+00:00","description":"\nInteger Overflow or Wraparound in GitHub repository radareorg/radare2 prior\nto 5.8.0.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"HIGH","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://huntr.dev/bounties/c6f8d3ef-5420-4eba-9a5f-aba5e2b5fea2","https://github.com/radareorg/radare2/commit/b53a1583d05c3a5bfe5fa60da133fe59dfbb02b8","https://www.cve.org/CVERecord?id=CVE-2022-4398"],"bugs":[""],"patches":{"radare2":[]},"tags":{},"packages":[{"name":"radare2","source":"https://ubuntu.com/security/cve?package=radare2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=radare2","debian":"https://tracker.debian.org/pkg/radare2","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-45145","published":"2022-12-10T16:15:00","updated_at":"2025-07-11T07:53:20.968356+00:00","description":"\negg-compile.scm in CHICKEN 5.x before 5.3.1 allows arbitrary OS command\nexecution during package installation via escape characters in a .egg file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://lists.gnu.org/archive/html/chicken-announce/2022-11/msg00000.html","https://code.call-cc.org/cgi-bin/gitweb.cgi?p=chicken-core.git;a=commitdiff;h=a08f8f548d772ef410c672ba33a27108d8d434f3;hp=9c6fb001c25de4390f46ffd7c3c94237f4df92a9","https://code.call-cc.org/cgi-bin/gitweb.cgi?p=chicken-core.git;a=blobdiff;f=egg-compile.scm;h=9ba4568113350ec75204cba55e43e27925e2d6fe;hp=c1f2ceb0fb470f63c2ba2a1cf9d8d40083c2359f;hb=a08f8f548d772ef410c672ba33a27108d8d434f3;hpb=9c6fb001c25de4390f46ffd7c3c94237f4df92a9","https://code.call-cc.org/cgi-bin/gitweb.cgi?p=chicken-core.git;a=blobdiff;f=NEWS;h=54888afff09353093453673c407cabfe76a5ce77;hp=a3fd88a892f82c8353267f50509d018bbb1934b9;hb=670478435a982fc4d1f001ea08669f53d35a51cd;hpb=a08f8f548d772ef410c672ba33a27108d8d434f3","https://www.cve.org/CVERecord?id=CVE-2022-45145"],"bugs":[""],"patches":{"chicken":[]},"tags":{},"packages":[{"name":"chicken","source":"https://ubuntu.com/security/cve?package=chicken","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chicken","debian":"https://tracker.debian.org/pkg/chicken","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-4396","published":"2022-12-10T12:15:00","updated_at":"2026-02-09T05:34:19.181614+00:00","description":"\nA vulnerability was found in RDFlib pyrdfa3 and classified as problematic.\nThis issue affects the function _get_option of the file pyRdfa/__init__.py.\nThe manipulation leads to cross site scripting. The attack may be initiated\nremotely. The name of the patch is\nffd1d62dd50d5f4190013b39cedcdfbd81f3ce3e. It is recommended to apply a\npatch to fix this issue. The identifier VDB-215249 was assigned to this\nvulnerability. NOTE: This vulnerability only affects products that are no\nlonger supported by the maintainer.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":3.5,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://github.com/RDFLib/pyrdfa3/commit/ffd1d62dd50d5f4190013b39cedcdfbd81f3ce3e","https://github.com/RDFLib/pyrdfa3/pull/40","https://www.cve.org/CVERecord?id=CVE-2022-4396"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1026051"],"patches":{"py":[],"python-pyrdfa":["upstream: https://github.com/RDFLib/pyrdfa3/commit/ffd1d62dd50d5f4190013b39cedcdfbd81f3ce3e"],"rdflib":[]},"tags":{},"packages":[{"name":"py","source":"https://ubuntu.com/security/cve?package=py","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=py","debian":"https://tracker.debian.org/pkg/py","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"python-pyrdfa","source":"https://ubuntu.com/security/cve?package=python-pyrdfa","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python-pyrdfa","debian":"https://tracker.debian.org/pkg/python-pyrdfa","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"3.5.2+20220504~ds-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.5.2+20220329~ds-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"rdflib","source":"https://ubuntu.com/security/cve?package=rdflib","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=rdflib","debian":"https://tracker.debian.org/pkg/rdflib","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-23485","published":"2022-12-10T01:15:00","updated_at":"2025-07-11T07:50:00.229261+00:00","description":"\nSentry is an error tracking and performance monitoring platform. In\nversions of the sentry python library prior to 22.11.0 an attacker with a\nknown valid invite link could manipulate a cookie to allow the same invite\nlink to be reused on multiple accounts when joining an organization. As a\nresult an attacker with a valid invite link can create multiple users and\njoin an organization they may not have been originally invited to. This\nissue was patched in version 22.11.0. Sentry SaaS customers do not need to\ntake action. Self-hosted Sentry installs on systems which can not upgrade\ncan disable the invite functionality until they are ready to deploy the\npatched version by editing their `sentry.conf.py` file (usually located at\n`~/.sentry/`).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:L","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":6.4,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/getsentry/sentry/security/advisories/GHSA-jv85-mqxj-3f9j","https://www.cve.org/CVERecord?id=CVE-2022-23485"],"bugs":[""],"patches":{"sentry-python":[]},"tags":{},"packages":[{"name":"sentry-python","source":"https://ubuntu.com/security/cve?package=sentry-python","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sentry-python","debian":"https://tracker.debian.org/pkg/sentry-python","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-4170","published":"2022-12-09T18:15:00","updated_at":"2025-07-11T07:52:41.932245+00:00","description":"\nThe rxvt-unicode package is vulnerable to a remote code execution, in the\nPerl background extension, when an attacker can control the data written to\nthe user's terminal and certain options are set.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.openwall.com/lists/oss-security/2022/12/05/1","http://cvs.schmorp.de/rxvt-unicode/src/perl/background?r1=1.105&r2=1.109","https://www.cve.org/CVERecord?id=CVE-2022-4170"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1025489"],"patches":{"rxvt-unicode":[]},"tags":{},"packages":[{"name":"rxvt-unicode","source":"https://ubuntu.com/security/cve?package=rxvt-unicode","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=rxvt-unicode","debian":"https://tracker.debian.org/pkg/rxvt-unicode","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-3724","published":"2022-12-09T18:15:00","updated_at":"2025-08-26T12:47:51.952530+00:00","description":"\nCrash in the USB HID protocol dissector in Wireshark 3.6.0 to 3.6.8 allows\ndenial of service via packet injection or crafted capture file on Windows","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":6.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.wireshark.org/security/wnpa-sec-2022-08.html","https://gitlab.com/wireshark/wireshark/-/issues/18384","https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3724.json","https://www.cve.org/CVERecord?id=CVE-2022-3724"],"bugs":[""],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.0.0-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"4.0.3-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"4.0.3-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"4.0.3-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"4.0.3-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"4.0.3-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"4.0.3-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-23493","published":"2022-12-09T18:15:00","updated_at":"2025-08-04T18:49:21.164767+00:00","description":"\nxrdp is an open source project which provides a graphical login to remote\nmachines using Microsoft Remote Desktop Protocol (RDP).\nxrdp < v0.9.21 contain a Out of Bound Read in\nxrdp_mm_trans_process_drdynvc_channel_close() function. There are no known\nworkarounds for this issue. Users are advised to upgrade.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":9.1,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-59wp-3wq6-jh5v","https://ubuntu.com/security/notices/USN-6474-1","https://www.cve.org/CVERecord?id=CVE-2022-23493"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1025879"],"patches":{"xrdp":[]},"tags":{},"packages":[{"name":"xrdp","source":"https://ubuntu.com/security/cve?package=xrdp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xrdp","debian":"https://tracker.debian.org/pkg/xrdp","statuses":[{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.9.21","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"0.9.12-1ubuntu0.1+esm1","component":null,"pocket":"esm-apps"},{"release_codename":"jammy","status":"released","description":"0.9.17-2ubuntu2+esm1","component":null,"pocket":"esm-apps"},{"release_codename":"noble","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-6474-1"],"notices":[{"id":"USN-6474-1","title":"xrdp vulnerabilities","summary":"Several security issues were fixed in xrdp.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2023-11-08T13:47:00.462142","description":"It was discovered that xrdp incorrectly handled validation of\nclient-supplied data, which could lead to out-of-bounds reads. An attacker\ncould possibly use this issue to crash the program or extract sensitive\ninformation. (CVE-2022-23479, CVE-2022-23481, CVE-2022-23483,\nCVE-2023-42822)\n\nIt was discovered that xrdp improperly handled session establishment\nerrors. An attacker could potentially use this issue to bypass the\nOS-level session restrictions by PAM. (CVE-2023-40184)\n\nIt was discovered that xrdp incorrectly handled validation of\nclient-supplied data, which could lead to out-of-bounds writes. An attacker\ncould possibly use this issue to cause memory corruption or execute\narbitrary code. This issue only affected Ubuntu 18.04 LTS,\nUbuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2022-23468)\n\nIt was discovered that xrdp incorrectly handled validation of\nclient-supplied data, which could lead to out-of-bounds reads. An attacker\ncould possibly use this issue to crash the program or extract sensitive\ninformation. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS\nand Ubuntu 22.04 LTS. (CVE-2022-23480, CVE-2022-23482, CVE-2022-23484)\n\nIt was discovered that xrdp incorrectly handled validation of\nclient-supplied data, which could lead to out-of-bounds reads. An attacker\ncould possibly use this issue to crash the program or extract sensitive\ninformation. This issue only affected Ubuntu 20.04 LTS and\nUbuntu 22.04 LTS. (CVE-2022-23477, CVE-2022-23493)\n\nIt was discovered that xrdp incorrectly handled validation of\nclient-supplied data, which could lead to out-of-bounds writes. An attacker\ncould possibly use this issue to cause memory corruption or execute\narbitrary code. This issue only affected Ubuntu 20.04 LTS and\nUbuntu 22.04 LTS. (CVE-2022-23478)\n\nIt was discovered that xrdp incorrectly handled validation of\nclient-supplied data, which could lead to out-of-bounds reads. An attacker\ncould possibly use this issue to crash the program or extract sensitive\ninformation. This issue only affected Ubuntu 22.04 LTS. (CVE-2022-23613)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"xrdp","version":"0.9.5-2ubuntu0.1~esm2","description":"Remote Desktop Protocol (RDP) server","is_source":true},{"name":"xorgxrdp","version":"0.9.5-2ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-apps"},{"name":"xrdp","version":"0.9.5-2ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-apps"},{"name":"xrdp-pulseaudio-installer","version":"0.9.5-2ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"xrdp","version":"0.9.12-1ubuntu0.1+esm1","description":"Remote Desktop Protocol (RDP) server","is_source":true},{"name":"xrdp","version":"0.9.12-1ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-apps"}],"jammy":[{"name":"xrdp","version":"0.9.17-2ubuntu2+esm1","description":"Remote Desktop Protocol (RDP) server","is_source":true},{"name":"xrdp","version":"0.9.17-2ubuntu2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-apps"}],"trusty":[{"name":"xrdp","version":"0.6.0-1ubuntu0.1+esm3","description":"Remote Desktop Protocol (RDP) server","is_source":true},{"name":"xrdp","version":"0.6.0-1ubuntu0.1+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-infra"}],"xenial":[{"name":"xrdp","version":"0.6.1-2ubuntu0.3+esm3","description":"Remote Desktop Protocol (RDP) server","is_source":true},{"name":"xrdp","version":"0.6.1-2ubuntu0.3+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2022-23468","CVE-2022-23477","CVE-2022-23479","CVE-2022-23484","CVE-2022-23481","CVE-2022-23613","CVE-2022-23493","CVE-2022-23480","CVE-2022-23483","CVE-2022-23478","CVE-2023-42822","CVE-2022-23482","CVE-2023-40184"]}]},{"id":"CVE-2022-23484","published":"2022-12-09T18:15:00","updated_at":"2025-08-04T18:49:21.164767+00:00","description":"\nxrdp is an open source project which provides a graphical login to remote\nmachines using Microsoft Remote Desktop Protocol (RDP).\nxrdp < v0.9.21 contain a Integer Overflow in\nxrdp_mm_process_rail_update_window_text() function. There are no known\nworkarounds for this issue. Users are advised to upgrade.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.2,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"HIGH","baseScore":8.2,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-rqfx-5fv8-q9c6","https://ubuntu.com/security/notices/USN-6474-1","https://www.cve.org/CVERecord?id=CVE-2022-23484"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1025879"],"patches":{"xrdp":[]},"tags":{},"packages":[{"name":"xrdp","source":"https://ubuntu.com/security/cve?package=xrdp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xrdp","debian":"https://tracker.debian.org/pkg/xrdp","statuses":[{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.9.21","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"0.9.5-2ubuntu0.1~esm2","component":null,"pocket":"esm-apps"},{"release_codename":"focal","status":"released","description":"0.9.12-1ubuntu0.1+esm1","component":null,"pocket":"esm-apps"},{"release_codename":"jammy","status":"released","description":"0.9.17-2ubuntu2+esm1","component":null,"pocket":"esm-apps"},{"release_codename":"noble","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-6474-1"],"notices":[{"id":"USN-6474-1","title":"xrdp vulnerabilities","summary":"Several security issues were fixed in xrdp.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2023-11-08T13:47:00.462142","description":"It was discovered that xrdp incorrectly handled validation of\nclient-supplied data, which could lead to out-of-bounds reads. An attacker\ncould possibly use this issue to crash the program or extract sensitive\ninformation. (CVE-2022-23479, CVE-2022-23481, CVE-2022-23483,\nCVE-2023-42822)\n\nIt was discovered that xrdp improperly handled session establishment\nerrors. An attacker could potentially use this issue to bypass the\nOS-level session restrictions by PAM. (CVE-2023-40184)\n\nIt was discovered that xrdp incorrectly handled validation of\nclient-supplied data, which could lead to out-of-bounds writes. An attacker\ncould possibly use this issue to cause memory corruption or execute\narbitrary code. This issue only affected Ubuntu 18.04 LTS,\nUbuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2022-23468)\n\nIt was discovered that xrdp incorrectly handled validation of\nclient-supplied data, which could lead to out-of-bounds reads. An attacker\ncould possibly use this issue to crash the program or extract sensitive\ninformation. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS\nand Ubuntu 22.04 LTS. (CVE-2022-23480, CVE-2022-23482, CVE-2022-23484)\n\nIt was discovered that xrdp incorrectly handled validation of\nclient-supplied data, which could lead to out-of-bounds reads. An attacker\ncould possibly use this issue to crash the program or extract sensitive\ninformation. This issue only affected Ubuntu 20.04 LTS and\nUbuntu 22.04 LTS. (CVE-2022-23477, CVE-2022-23493)\n\nIt was discovered that xrdp incorrectly handled validation of\nclient-supplied data, which could lead to out-of-bounds writes. An attacker\ncould possibly use this issue to cause memory corruption or execute\narbitrary code. This issue only affected Ubuntu 20.04 LTS and\nUbuntu 22.04 LTS. (CVE-2022-23478)\n\nIt was discovered that xrdp incorrectly handled validation of\nclient-supplied data, which could lead to out-of-bounds reads. An attacker\ncould possibly use this issue to crash the program or extract sensitive\ninformation. This issue only affected Ubuntu 22.04 LTS. (CVE-2022-23613)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"xrdp","version":"0.9.5-2ubuntu0.1~esm2","description":"Remote Desktop Protocol (RDP) server","is_source":true},{"name":"xorgxrdp","version":"0.9.5-2ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-apps"},{"name":"xrdp","version":"0.9.5-2ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-apps"},{"name":"xrdp-pulseaudio-installer","version":"0.9.5-2ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"xrdp","version":"0.9.12-1ubuntu0.1+esm1","description":"Remote Desktop Protocol (RDP) server","is_source":true},{"name":"xrdp","version":"0.9.12-1ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-apps"}],"jammy":[{"name":"xrdp","version":"0.9.17-2ubuntu2+esm1","description":"Remote Desktop Protocol (RDP) server","is_source":true},{"name":"xrdp","version":"0.9.17-2ubuntu2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-apps"}],"trusty":[{"name":"xrdp","version":"0.6.0-1ubuntu0.1+esm3","description":"Remote Desktop Protocol (RDP) server","is_source":true},{"name":"xrdp","version":"0.6.0-1ubuntu0.1+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-infra"}],"xenial":[{"name":"xrdp","version":"0.6.1-2ubuntu0.3+esm3","description":"Remote Desktop Protocol (RDP) server","is_source":true},{"name":"xrdp","version":"0.6.1-2ubuntu0.3+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2022-23468","CVE-2022-23477","CVE-2022-23479","CVE-2022-23484","CVE-2022-23481","CVE-2022-23613","CVE-2022-23493","CVE-2022-23480","CVE-2022-23483","CVE-2022-23478","CVE-2023-42822","CVE-2022-23482","CVE-2023-40184"]}]},{"id":"CVE-2022-23483","published":"2022-12-09T18:15:00","updated_at":"2025-08-04T18:49:19.269793+00:00","description":"\nxrdp is an open source project which provides a graphical login to remote\nmachines using Microsoft Remote Desktop Protocol (RDP).\nxrdp < v0.9.21 contain a Out of Bound Read in libxrdp_send_to_channel()\nfunction. There are no known workarounds for this issue. Users are advised\nto upgrade.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-38rw-9ch2-fcxq","https://ubuntu.com/security/notices/USN-6474-1","https://www.cve.org/CVERecord?id=CVE-2022-23483"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1025879"],"patches":{"xrdp":[]},"tags":{},"packages":[{"name":"xrdp","source":"https://ubuntu.com/security/cve?package=xrdp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xrdp","debian":"https://tracker.debian.org/pkg/xrdp","statuses":[{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.9.21","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"0.9.5-2ubuntu0.1~esm2","component":null,"pocket":"esm-apps"},{"release_codename":"focal","status":"released","description":"0.9.12-1ubuntu0.1+esm1","component":null,"pocket":"esm-apps"},{"release_codename":"jammy","status":"released","description":"0.9.17-2ubuntu2+esm1","component":null,"pocket":"esm-apps"},{"release_codename":"trusty","status":"released","description":"0.6.0-1ubuntu0.1+esm3","component":null,"pocket":"esm-infra"},{"release_codename":"xenial","status":"released","description":"0.6.1-2ubuntu0.3+esm3","component":null,"pocket":"esm-apps"},{"release_codename":"noble","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-6474-1"],"notices":[{"id":"USN-6474-1","title":"xrdp vulnerabilities","summary":"Several security issues were fixed in xrdp.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2023-11-08T13:47:00.462142","description":"It was discovered that xrdp incorrectly handled validation of\nclient-supplied data, which could lead to out-of-bounds reads. An attacker\ncould possibly use this issue to crash the program or extract sensitive\ninformation. (CVE-2022-23479, CVE-2022-23481, CVE-2022-23483,\nCVE-2023-42822)\n\nIt was discovered that xrdp improperly handled session establishment\nerrors. An attacker could potentially use this issue to bypass the\nOS-level session restrictions by PAM. (CVE-2023-40184)\n\nIt was discovered that xrdp incorrectly handled validation of\nclient-supplied data, which could lead to out-of-bounds writes. An attacker\ncould possibly use this issue to cause memory corruption or execute\narbitrary code. This issue only affected Ubuntu 18.04 LTS,\nUbuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2022-23468)\n\nIt was discovered that xrdp incorrectly handled validation of\nclient-supplied data, which could lead to out-of-bounds reads. An attacker\ncould possibly use this issue to crash the program or extract sensitive\ninformation. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS\nand Ubuntu 22.04 LTS. (CVE-2022-23480, CVE-2022-23482, CVE-2022-23484)\n\nIt was discovered that xrdp incorrectly handled validation of\nclient-supplied data, which could lead to out-of-bounds reads. An attacker\ncould possibly use this issue to crash the program or extract sensitive\ninformation. This issue only affected Ubuntu 20.04 LTS and\nUbuntu 22.04 LTS. (CVE-2022-23477, CVE-2022-23493)\n\nIt was discovered that xrdp incorrectly handled validation of\nclient-supplied data, which could lead to out-of-bounds writes. An attacker\ncould possibly use this issue to cause memory corruption or execute\narbitrary code. This issue only affected Ubuntu 20.04 LTS and\nUbuntu 22.04 LTS. (CVE-2022-23478)\n\nIt was discovered that xrdp incorrectly handled validation of\nclient-supplied data, which could lead to out-of-bounds reads. An attacker\ncould possibly use this issue to crash the program or extract sensitive\ninformation. This issue only affected Ubuntu 22.04 LTS. (CVE-2022-23613)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"xrdp","version":"0.9.5-2ubuntu0.1~esm2","description":"Remote Desktop Protocol (RDP) server","is_source":true},{"name":"xorgxrdp","version":"0.9.5-2ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-apps"},{"name":"xrdp","version":"0.9.5-2ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-apps"},{"name":"xrdp-pulseaudio-installer","version":"0.9.5-2ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"xrdp","version":"0.9.12-1ubuntu0.1+esm1","description":"Remote Desktop Protocol (RDP) server","is_source":true},{"name":"xrdp","version":"0.9.12-1ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-apps"}],"jammy":[{"name":"xrdp","version":"0.9.17-2ubuntu2+esm1","description":"Remote Desktop Protocol (RDP) server","is_source":true},{"name":"xrdp","version":"0.9.17-2ubuntu2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-apps"}],"trusty":[{"name":"xrdp","version":"0.6.0-1ubuntu0.1+esm3","description":"Remote Desktop Protocol (RDP) server","is_source":true},{"name":"xrdp","version":"0.6.0-1ubuntu0.1+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-infra"}],"xenial":[{"name":"xrdp","version":"0.6.1-2ubuntu0.3+esm3","description":"Remote Desktop Protocol (RDP) server","is_source":true},{"name":"xrdp","version":"0.6.1-2ubuntu0.3+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2022-23468","CVE-2022-23477","CVE-2022-23479","CVE-2022-23484","CVE-2022-23481","CVE-2022-23613","CVE-2022-23493","CVE-2022-23480","CVE-2022-23483","CVE-2022-23478","CVE-2023-42822","CVE-2022-23482","CVE-2023-40184"]}]},{"id":"CVE-2022-23482","published":"2022-12-09T18:15:00","updated_at":"2025-08-04T18:49:19.269793+00:00","description":"\nxrdp is an open source project which provides a graphical login to remote\nmachines using Microsoft Remote Desktop Protocol (RDP).\nxrdp < v0.9.21 contain a Out of Bound Read in\nxrdp_sec_process_mcs_data_CS_CORE() function. There are no known\nworkarounds for this issue. Users are advised to upgrade.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":0.0,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":0.0,"baseSeverity":"NONE"}}},"status":"active","mitigation":"","references":["https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-56pq-2pm9-7fhm","https://ubuntu.com/security/notices/USN-6474-1","https://www.cve.org/CVERecord?id=CVE-2022-23482"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1025879"],"patches":{"xrdp":[]},"tags":{},"packages":[{"name":"xrdp","source":"https://ubuntu.com/security/cve?package=xrdp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xrdp","debian":"https://tracker.debian.org/pkg/xrdp","statuses":[{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.9.21","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"0.9.5-2ubuntu0.1~esm2","component":null,"pocket":"esm-apps"},{"release_codename":"focal","status":"released","description":"0.9.12-1ubuntu0.1+esm1","component":null,"pocket":"esm-apps"},{"release_codename":"jammy","status":"released","description":"0.9.17-2ubuntu2+esm1","component":null,"pocket":"esm-apps"},{"release_codename":"noble","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-6474-1"],"notices":[{"id":"USN-6474-1","title":"xrdp vulnerabilities","summary":"Several security issues were fixed in xrdp.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2023-11-08T13:47:00.462142","description":"It was discovered that xrdp incorrectly handled validation of\nclient-supplied data, which could lead to out-of-bounds reads. An attacker\ncould possibly use this issue to crash the program or extract sensitive\ninformation. (CVE-2022-23479, CVE-2022-23481, CVE-2022-23483,\nCVE-2023-42822)\n\nIt was discovered that xrdp improperly handled session establishment\nerrors. An attacker could potentially use this issue to bypass the\nOS-level session restrictions by PAM. (CVE-2023-40184)\n\nIt was discovered that xrdp incorrectly handled validation of\nclient-supplied data, which could lead to out-of-bounds writes. An attacker\ncould possibly use this issue to cause memory corruption or execute\narbitrary code. This issue only affected Ubuntu 18.04 LTS,\nUbuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2022-23468)\n\nIt was discovered that xrdp incorrectly handled validation of\nclient-supplied data, which could lead to out-of-bounds reads. An attacker\ncould possibly use this issue to crash the program or extract sensitive\ninformation. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS\nand Ubuntu 22.04 LTS. (CVE-2022-23480, CVE-2022-23482, CVE-2022-23484)\n\nIt was discovered that xrdp incorrectly handled validation of\nclient-supplied data, which could lead to out-of-bounds reads. An attacker\ncould possibly use this issue to crash the program or extract sensitive\ninformation. This issue only affected Ubuntu 20.04 LTS and\nUbuntu 22.04 LTS. (CVE-2022-23477, CVE-2022-23493)\n\nIt was discovered that xrdp incorrectly handled validation of\nclient-supplied data, which could lead to out-of-bounds writes. An attacker\ncould possibly use this issue to cause memory corruption or execute\narbitrary code. This issue only affected Ubuntu 20.04 LTS and\nUbuntu 22.04 LTS. (CVE-2022-23478)\n\nIt was discovered that xrdp incorrectly handled validation of\nclient-supplied data, which could lead to out-of-bounds reads. An attacker\ncould possibly use this issue to crash the program or extract sensitive\ninformation. This issue only affected Ubuntu 22.04 LTS. (CVE-2022-23613)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"xrdp","version":"0.9.5-2ubuntu0.1~esm2","description":"Remote Desktop Protocol (RDP) server","is_source":true},{"name":"xorgxrdp","version":"0.9.5-2ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-apps"},{"name":"xrdp","version":"0.9.5-2ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-apps"},{"name":"xrdp-pulseaudio-installer","version":"0.9.5-2ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"xrdp","version":"0.9.12-1ubuntu0.1+esm1","description":"Remote Desktop Protocol (RDP) server","is_source":true},{"name":"xrdp","version":"0.9.12-1ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-apps"}],"jammy":[{"name":"xrdp","version":"0.9.17-2ubuntu2+esm1","description":"Remote Desktop Protocol (RDP) server","is_source":true},{"name":"xrdp","version":"0.9.17-2ubuntu2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-apps"}],"trusty":[{"name":"xrdp","version":"0.6.0-1ubuntu0.1+esm3","description":"Remote Desktop Protocol (RDP) server","is_source":true},{"name":"xrdp","version":"0.6.0-1ubuntu0.1+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-infra"}],"xenial":[{"name":"xrdp","version":"0.6.1-2ubuntu0.3+esm3","description":"Remote Desktop Protocol (RDP) server","is_source":true},{"name":"xrdp","version":"0.6.1-2ubuntu0.3+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2022-23468","CVE-2022-23477","CVE-2022-23479","CVE-2022-23484","CVE-2022-23481","CVE-2022-23613","CVE-2022-23493","CVE-2022-23480","CVE-2022-23483","CVE-2022-23478","CVE-2023-42822","CVE-2022-23482","CVE-2023-40184"]}]},{"id":"CVE-2022-23481","published":"2022-12-09T18:15:00","updated_at":"2025-08-04T18:49:19.269793+00:00","description":"\nxrdp is an open source project which provides a graphical login to remote\nmachines using Microsoft Remote Desktop Protocol (RDP).\nxrdp < v0.9.21 contain a Out of Bound Read in\nxrdp_caps_process_confirm_active() function. There are no known workarounds\nfor this issue. Users are advised to upgrade.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":0.0,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":0.0,"baseSeverity":"NONE"}}},"status":"active","mitigation":"","references":["https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-hm75-9jcg-p7hq","https://ubuntu.com/security/notices/USN-6474-1","https://www.cve.org/CVERecord?id=CVE-2022-23481"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1025879"],"patches":{"xrdp":[]},"tags":{},"packages":[{"name":"xrdp","source":"https://ubuntu.com/security/cve?package=xrdp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xrdp","debian":"https://tracker.debian.org/pkg/xrdp","statuses":[{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.9.21","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"0.9.5-2ubuntu0.1~esm2","component":null,"pocket":"esm-apps"},{"release_codename":"focal","status":"released","description":"0.9.12-1ubuntu0.1+esm1","component":null,"pocket":"esm-apps"},{"release_codename":"jammy","status":"released","description":"0.9.17-2ubuntu2+esm1","component":null,"pocket":"esm-apps"},{"release_codename":"trusty","status":"released","description":"0.6.0-1ubuntu0.1+esm3","component":null,"pocket":"esm-infra"},{"release_codename":"xenial","status":"released","description":"0.6.1-2ubuntu0.3+esm3","component":null,"pocket":"esm-apps"},{"release_codename":"noble","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-6474-1"],"notices":[{"id":"USN-6474-1","title":"xrdp vulnerabilities","summary":"Several security issues were fixed in xrdp.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2023-11-08T13:47:00.462142","description":"It was discovered that xrdp incorrectly handled validation of\nclient-supplied data, which could lead to out-of-bounds reads. An attacker\ncould possibly use this issue to crash the program or extract sensitive\ninformation. (CVE-2022-23479, CVE-2022-23481, CVE-2022-23483,\nCVE-2023-42822)\n\nIt was discovered that xrdp improperly handled session establishment\nerrors. An attacker could potentially use this issue to bypass the\nOS-level session restrictions by PAM. (CVE-2023-40184)\n\nIt was discovered that xrdp incorrectly handled validation of\nclient-supplied data, which could lead to out-of-bounds writes. An attacker\ncould possibly use this issue to cause memory corruption or execute\narbitrary code. This issue only affected Ubuntu 18.04 LTS,\nUbuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2022-23468)\n\nIt was discovered that xrdp incorrectly handled validation of\nclient-supplied data, which could lead to out-of-bounds reads. An attacker\ncould possibly use this issue to crash the program or extract sensitive\ninformation. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS\nand Ubuntu 22.04 LTS. (CVE-2022-23480, CVE-2022-23482, CVE-2022-23484)\n\nIt was discovered that xrdp incorrectly handled validation of\nclient-supplied data, which could lead to out-of-bounds reads. An attacker\ncould possibly use this issue to crash the program or extract sensitive\ninformation. This issue only affected Ubuntu 20.04 LTS and\nUbuntu 22.04 LTS. (CVE-2022-23477, CVE-2022-23493)\n\nIt was discovered that xrdp incorrectly handled validation of\nclient-supplied data, which could lead to out-of-bounds writes. An attacker\ncould possibly use this issue to cause memory corruption or execute\narbitrary code. This issue only affected Ubuntu 20.04 LTS and\nUbuntu 22.04 LTS. (CVE-2022-23478)\n\nIt was discovered that xrdp incorrectly handled validation of\nclient-supplied data, which could lead to out-of-bounds reads. An attacker\ncould possibly use this issue to crash the program or extract sensitive\ninformation. This issue only affected Ubuntu 22.04 LTS. (CVE-2022-23613)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"xrdp","version":"0.9.5-2ubuntu0.1~esm2","description":"Remote Desktop Protocol (RDP) server","is_source":true},{"name":"xorgxrdp","version":"0.9.5-2ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-apps"},{"name":"xrdp","version":"0.9.5-2ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-apps"},{"name":"xrdp-pulseaudio-installer","version":"0.9.5-2ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"xrdp","version":"0.9.12-1ubuntu0.1+esm1","description":"Remote Desktop Protocol (RDP) server","is_source":true},{"name":"xrdp","version":"0.9.12-1ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-apps"}],"jammy":[{"name":"xrdp","version":"0.9.17-2ubuntu2+esm1","description":"Remote Desktop Protocol (RDP) server","is_source":true},{"name":"xrdp","version":"0.9.17-2ubuntu2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-apps"}],"trusty":[{"name":"xrdp","version":"0.6.0-1ubuntu0.1+esm3","description":"Remote Desktop Protocol (RDP) server","is_source":true},{"name":"xrdp","version":"0.6.0-1ubuntu0.1+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-infra"}],"xenial":[{"name":"xrdp","version":"0.6.1-2ubuntu0.3+esm3","description":"Remote Desktop Protocol (RDP) server","is_source":true},{"name":"xrdp","version":"0.6.1-2ubuntu0.3+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2022-23468","CVE-2022-23477","CVE-2022-23479","CVE-2022-23484","CVE-2022-23481","CVE-2022-23613","CVE-2022-23493","CVE-2022-23480","CVE-2022-23483","CVE-2022-23478","CVE-2023-42822","CVE-2022-23482","CVE-2023-40184"]}]},{"id":"CVE-2022-23480","published":"2022-12-09T18:15:00","updated_at":"2025-08-04T18:49:19.269793+00:00","description":"\nxrdp is an open source project which provides a graphical login to remote\nmachines using Microsoft Remote Desktop Protocol (RDP).\nxrdp < v0.9.21 contain a buffer over flow in\ndevredir_proc_client_devlist_announce_req() function. There are no known\nworkarounds for this issue. Users are advised to upgrade.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.1,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-3jmx-f6hv-95wg","https://ubuntu.com/security/notices/USN-6474-1","https://www.cve.org/CVERecord?id=CVE-2022-23480"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1025879"],"patches":{"xrdp":[]},"tags":{},"packages":[{"name":"xrdp","source":"https://ubuntu.com/security/cve?package=xrdp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xrdp","debian":"https://tracker.debian.org/pkg/xrdp","statuses":[{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.9.21","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"0.9.5-2ubuntu0.1~esm2","component":null,"pocket":"esm-apps"},{"release_codename":"focal","status":"released","description":"0.9.12-1ubuntu0.1+esm1","component":null,"pocket":"esm-apps"},{"release_codename":"jammy","status":"released","description":"0.9.17-2ubuntu2+esm1","component":null,"pocket":"esm-apps"},{"release_codename":"noble","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-6474-1"],"notices":[{"id":"USN-6474-1","title":"xrdp vulnerabilities","summary":"Several security issues were fixed in xrdp.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2023-11-08T13:47:00.462142","description":"It was discovered that xrdp incorrectly handled validation of\nclient-supplied data, which could lead to out-of-bounds reads. An attacker\ncould possibly use this issue to crash the program or extract sensitive\ninformation. (CVE-2022-23479, CVE-2022-23481, CVE-2022-23483,\nCVE-2023-42822)\n\nIt was discovered that xrdp improperly handled session establishment\nerrors. An attacker could potentially use this issue to bypass the\nOS-level session restrictions by PAM. (CVE-2023-40184)\n\nIt was discovered that xrdp incorrectly handled validation of\nclient-supplied data, which could lead to out-of-bounds writes. An attacker\ncould possibly use this issue to cause memory corruption or execute\narbitrary code. This issue only affected Ubuntu 18.04 LTS,\nUbuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2022-23468)\n\nIt was discovered that xrdp incorrectly handled validation of\nclient-supplied data, which could lead to out-of-bounds reads. An attacker\ncould possibly use this issue to crash the program or extract sensitive\ninformation. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS\nand Ubuntu 22.04 LTS. (CVE-2022-23480, CVE-2022-23482, CVE-2022-23484)\n\nIt was discovered that xrdp incorrectly handled validation of\nclient-supplied data, which could lead to out-of-bounds reads. An attacker\ncould possibly use this issue to crash the program or extract sensitive\ninformation. This issue only affected Ubuntu 20.04 LTS and\nUbuntu 22.04 LTS. (CVE-2022-23477, CVE-2022-23493)\n\nIt was discovered that xrdp incorrectly handled validation of\nclient-supplied data, which could lead to out-of-bounds writes. An attacker\ncould possibly use this issue to cause memory corruption or execute\narbitrary code. This issue only affected Ubuntu 20.04 LTS and\nUbuntu 22.04 LTS. (CVE-2022-23478)\n\nIt was discovered that xrdp incorrectly handled validation of\nclient-supplied data, which could lead to out-of-bounds reads. An attacker\ncould possibly use this issue to crash the program or extract sensitive\ninformation. This issue only affected Ubuntu 22.04 LTS. (CVE-2022-23613)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"xrdp","version":"0.9.5-2ubuntu0.1~esm2","description":"Remote Desktop Protocol (RDP) server","is_source":true},{"name":"xorgxrdp","version":"0.9.5-2ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-apps"},{"name":"xrdp","version":"0.9.5-2ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-apps"},{"name":"xrdp-pulseaudio-installer","version":"0.9.5-2ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"xrdp","version":"0.9.12-1ubuntu0.1+esm1","description":"Remote Desktop Protocol (RDP) server","is_source":true},{"name":"xrdp","version":"0.9.12-1ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-apps"}],"jammy":[{"name":"xrdp","version":"0.9.17-2ubuntu2+esm1","description":"Remote Desktop Protocol (RDP) server","is_source":true},{"name":"xrdp","version":"0.9.17-2ubuntu2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-apps"}],"trusty":[{"name":"xrdp","version":"0.6.0-1ubuntu0.1+esm3","description":"Remote Desktop Protocol (RDP) server","is_source":true},{"name":"xrdp","version":"0.6.0-1ubuntu0.1+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-infra"}],"xenial":[{"name":"xrdp","version":"0.6.1-2ubuntu0.3+esm3","description":"Remote Desktop Protocol (RDP) server","is_source":true},{"name":"xrdp","version":"0.6.1-2ubuntu0.3+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2022-23468","CVE-2022-23477","CVE-2022-23479","CVE-2022-23484","CVE-2022-23481","CVE-2022-23613","CVE-2022-23493","CVE-2022-23480","CVE-2022-23483","CVE-2022-23478","CVE-2023-42822","CVE-2022-23482","CVE-2023-40184"]}]},{"id":"CVE-2022-23479","published":"2022-12-09T18:15:00","updated_at":"2025-08-04T18:49:19.269793+00:00","description":"\nxrdp is an open source project which provides a graphical login to remote\nmachines using Microsoft Remote Desktop Protocol (RDP).\nxrdp < v0.9.21 contain a buffer over flow in xrdp_mm_chan_data_in()\nfunction. There are no known workarounds for this issue. Users are advised\nto upgrade.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.1,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-pgx2-3fjj-fqqh","https://ubuntu.com/security/notices/USN-6474-1","https://www.cve.org/CVERecord?id=CVE-2022-23479"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1025879"],"patches":{"xrdp":[]},"tags":{},"packages":[{"name":"xrdp","source":"https://ubuntu.com/security/cve?package=xrdp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xrdp","debian":"https://tracker.debian.org/pkg/xrdp","statuses":[{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.9.21","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"0.9.5-2ubuntu0.1~esm2","component":null,"pocket":"esm-apps"},{"release_codename":"focal","status":"released","description":"0.9.12-1ubuntu0.1+esm1","component":null,"pocket":"esm-apps"},{"release_codename":"jammy","status":"released","description":"0.9.17-2ubuntu2+esm1","component":null,"pocket":"esm-apps"},{"release_codename":"trusty","status":"released","description":"0.6.0-1ubuntu0.1+esm3","component":null,"pocket":"esm-infra"},{"release_codename":"xenial","status":"released","description":"0.6.1-2ubuntu0.3+esm3","component":null,"pocket":"esm-apps"},{"release_codename":"noble","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-6474-1"],"notices":[{"id":"USN-6474-1","title":"xrdp vulnerabilities","summary":"Several security issues were fixed in xrdp.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2023-11-08T13:47:00.462142","description":"It was discovered that xrdp incorrectly handled validation of\nclient-supplied data, which could lead to out-of-bounds reads. An attacker\ncould possibly use this issue to crash the program or extract sensitive\ninformation. (CVE-2022-23479, CVE-2022-23481, CVE-2022-23483,\nCVE-2023-42822)\n\nIt was discovered that xrdp improperly handled session establishment\nerrors. An attacker could potentially use this issue to bypass the\nOS-level session restrictions by PAM. (CVE-2023-40184)\n\nIt was discovered that xrdp incorrectly handled validation of\nclient-supplied data, which could lead to out-of-bounds writes. An attacker\ncould possibly use this issue to cause memory corruption or execute\narbitrary code. This issue only affected Ubuntu 18.04 LTS,\nUbuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2022-23468)\n\nIt was discovered that xrdp incorrectly handled validation of\nclient-supplied data, which could lead to out-of-bounds reads. An attacker\ncould possibly use this issue to crash the program or extract sensitive\ninformation. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS\nand Ubuntu 22.04 LTS. (CVE-2022-23480, CVE-2022-23482, CVE-2022-23484)\n\nIt was discovered that xrdp incorrectly handled validation of\nclient-supplied data, which could lead to out-of-bounds reads. An attacker\ncould possibly use this issue to crash the program or extract sensitive\ninformation. This issue only affected Ubuntu 20.04 LTS and\nUbuntu 22.04 LTS. (CVE-2022-23477, CVE-2022-23493)\n\nIt was discovered that xrdp incorrectly handled validation of\nclient-supplied data, which could lead to out-of-bounds writes. An attacker\ncould possibly use this issue to cause memory corruption or execute\narbitrary code. This issue only affected Ubuntu 20.04 LTS and\nUbuntu 22.04 LTS. (CVE-2022-23478)\n\nIt was discovered that xrdp incorrectly handled validation of\nclient-supplied data, which could lead to out-of-bounds reads. An attacker\ncould possibly use this issue to crash the program or extract sensitive\ninformation. This issue only affected Ubuntu 22.04 LTS. (CVE-2022-23613)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"xrdp","version":"0.9.5-2ubuntu0.1~esm2","description":"Remote Desktop Protocol (RDP) server","is_source":true},{"name":"xorgxrdp","version":"0.9.5-2ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-apps"},{"name":"xrdp","version":"0.9.5-2ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-apps"},{"name":"xrdp-pulseaudio-installer","version":"0.9.5-2ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"xrdp","version":"0.9.12-1ubuntu0.1+esm1","description":"Remote Desktop Protocol (RDP) server","is_source":true},{"name":"xrdp","version":"0.9.12-1ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-apps"}],"jammy":[{"name":"xrdp","version":"0.9.17-2ubuntu2+esm1","description":"Remote Desktop Protocol (RDP) server","is_source":true},{"name":"xrdp","version":"0.9.17-2ubuntu2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-apps"}],"trusty":[{"name":"xrdp","version":"0.6.0-1ubuntu0.1+esm3","description":"Remote Desktop Protocol (RDP) server","is_source":true},{"name":"xrdp","version":"0.6.0-1ubuntu0.1+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-infra"}],"xenial":[{"name":"xrdp","version":"0.6.1-2ubuntu0.3+esm3","description":"Remote Desktop Protocol (RDP) server","is_source":true},{"name":"xrdp","version":"0.6.1-2ubuntu0.3+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2022-23468","CVE-2022-23477","CVE-2022-23479","CVE-2022-23484","CVE-2022-23481","CVE-2022-23613","CVE-2022-23493","CVE-2022-23480","CVE-2022-23483","CVE-2022-23478","CVE-2023-42822","CVE-2022-23482","CVE-2023-40184"]}]},{"id":"CVE-2022-23478","published":"2022-12-09T18:15:00","updated_at":"2025-08-04T18:49:19.269793+00:00","description":"\nxrdp is an open source project which provides a graphical login to remote\nmachines using Microsoft Remote Desktop Protocol (RDP).\nxrdp < v0.9.21 contain a Out of Bound Write in\nxrdp_mm_trans_process_drdynvc_channel_open() function. There are no known\nworkarounds for this issue. Users are advised to upgrade.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.1,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-2f49-wwpm-78pj","https://ubuntu.com/security/notices/USN-6474-1","https://www.cve.org/CVERecord?id=CVE-2022-23478"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1025879"],"patches":{"xrdp":[]},"tags":{},"packages":[{"name":"xrdp","source":"https://ubuntu.com/security/cve?package=xrdp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xrdp","debian":"https://tracker.debian.org/pkg/xrdp","statuses":[{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.9.21","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"0.9.12-1ubuntu0.1+esm1","component":null,"pocket":"esm-apps"},{"release_codename":"jammy","status":"released","description":"0.9.17-2ubuntu2+esm1","component":null,"pocket":"esm-apps"},{"release_codename":"noble","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-6474-1"],"notices":[{"id":"USN-6474-1","title":"xrdp vulnerabilities","summary":"Several security issues were fixed in xrdp.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2023-11-08T13:47:00.462142","description":"It was discovered that xrdp incorrectly handled validation of\nclient-supplied data, which could lead to out-of-bounds reads. An attacker\ncould possibly use this issue to crash the program or extract sensitive\ninformation. (CVE-2022-23479, CVE-2022-23481, CVE-2022-23483,\nCVE-2023-42822)\n\nIt was discovered that xrdp improperly handled session establishment\nerrors. An attacker could potentially use this issue to bypass the\nOS-level session restrictions by PAM. (CVE-2023-40184)\n\nIt was discovered that xrdp incorrectly handled validation of\nclient-supplied data, which could lead to out-of-bounds writes. An attacker\ncould possibly use this issue to cause memory corruption or execute\narbitrary code. This issue only affected Ubuntu 18.04 LTS,\nUbuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2022-23468)\n\nIt was discovered that xrdp incorrectly handled validation of\nclient-supplied data, which could lead to out-of-bounds reads. An attacker\ncould possibly use this issue to crash the program or extract sensitive\ninformation. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS\nand Ubuntu 22.04 LTS. (CVE-2022-23480, CVE-2022-23482, CVE-2022-23484)\n\nIt was discovered that xrdp incorrectly handled validation of\nclient-supplied data, which could lead to out-of-bounds reads. An attacker\ncould possibly use this issue to crash the program or extract sensitive\ninformation. This issue only affected Ubuntu 20.04 LTS and\nUbuntu 22.04 LTS. (CVE-2022-23477, CVE-2022-23493)\n\nIt was discovered that xrdp incorrectly handled validation of\nclient-supplied data, which could lead to out-of-bounds writes. An attacker\ncould possibly use this issue to cause memory corruption or execute\narbitrary code. This issue only affected Ubuntu 20.04 LTS and\nUbuntu 22.04 LTS. (CVE-2022-23478)\n\nIt was discovered that xrdp incorrectly handled validation of\nclient-supplied data, which could lead to out-of-bounds reads. An attacker\ncould possibly use this issue to crash the program or extract sensitive\ninformation. This issue only affected Ubuntu 22.04 LTS. (CVE-2022-23613)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"xrdp","version":"0.9.5-2ubuntu0.1~esm2","description":"Remote Desktop Protocol (RDP) server","is_source":true},{"name":"xorgxrdp","version":"0.9.5-2ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-apps"},{"name":"xrdp","version":"0.9.5-2ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-apps"},{"name":"xrdp-pulseaudio-installer","version":"0.9.5-2ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"xrdp","version":"0.9.12-1ubuntu0.1+esm1","description":"Remote Desktop Protocol (RDP) server","is_source":true},{"name":"xrdp","version":"0.9.12-1ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-apps"}],"jammy":[{"name":"xrdp","version":"0.9.17-2ubuntu2+esm1","description":"Remote Desktop Protocol (RDP) server","is_source":true},{"name":"xrdp","version":"0.9.17-2ubuntu2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-apps"}],"trusty":[{"name":"xrdp","version":"0.6.0-1ubuntu0.1+esm3","description":"Remote Desktop Protocol (RDP) server","is_source":true},{"name":"xrdp","version":"0.6.0-1ubuntu0.1+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-infra"}],"xenial":[{"name":"xrdp","version":"0.6.1-2ubuntu0.3+esm3","description":"Remote Desktop Protocol (RDP) server","is_source":true},{"name":"xrdp","version":"0.6.1-2ubuntu0.3+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2022-23468","CVE-2022-23477","CVE-2022-23479","CVE-2022-23484","CVE-2022-23481","CVE-2022-23613","CVE-2022-23493","CVE-2022-23480","CVE-2022-23483","CVE-2022-23478","CVE-2023-42822","CVE-2022-23482","CVE-2023-40184"]}]},{"id":"CVE-2022-23477","published":"2022-12-09T18:15:00","updated_at":"2025-08-04T18:49:19.269793+00:00","description":"\nxrdp is an open source project which provides a graphical login to remote\nmachines using Microsoft Remote Desktop Protocol (RDP).\nxrdp < v0.9.21 contain a buffer over flow in audin_send_open() function.\nThere are no known workarounds for this issue. Users are advised to\nupgrade.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.1,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-hqw2-jx2c-wrr2","https://ubuntu.com/security/notices/USN-6474-1","https://www.cve.org/CVERecord?id=CVE-2022-23477"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1025879"],"patches":{"xrdp":[]},"tags":{},"packages":[{"name":"xrdp","source":"https://ubuntu.com/security/cve?package=xrdp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xrdp","debian":"https://tracker.debian.org/pkg/xrdp","statuses":[{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.9.21","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"0.9.12-1ubuntu0.1+esm1","component":null,"pocket":"esm-apps"},{"release_codename":"jammy","status":"released","description":"0.9.17-2ubuntu2+esm1","component":null,"pocket":"esm-apps"},{"release_codename":"noble","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-6474-1"],"notices":[{"id":"USN-6474-1","title":"xrdp vulnerabilities","summary":"Several security issues were fixed in xrdp.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2023-11-08T13:47:00.462142","description":"It was discovered that xrdp incorrectly handled validation of\nclient-supplied data, which could lead to out-of-bounds reads. An attacker\ncould possibly use this issue to crash the program or extract sensitive\ninformation. (CVE-2022-23479, CVE-2022-23481, CVE-2022-23483,\nCVE-2023-42822)\n\nIt was discovered that xrdp improperly handled session establishment\nerrors. An attacker could potentially use this issue to bypass the\nOS-level session restrictions by PAM. (CVE-2023-40184)\n\nIt was discovered that xrdp incorrectly handled validation of\nclient-supplied data, which could lead to out-of-bounds writes. An attacker\ncould possibly use this issue to cause memory corruption or execute\narbitrary code. This issue only affected Ubuntu 18.04 LTS,\nUbuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2022-23468)\n\nIt was discovered that xrdp incorrectly handled validation of\nclient-supplied data, which could lead to out-of-bounds reads. An attacker\ncould possibly use this issue to crash the program or extract sensitive\ninformation. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS\nand Ubuntu 22.04 LTS. (CVE-2022-23480, CVE-2022-23482, CVE-2022-23484)\n\nIt was discovered that xrdp incorrectly handled validation of\nclient-supplied data, which could lead to out-of-bounds reads. An attacker\ncould possibly use this issue to crash the program or extract sensitive\ninformation. This issue only affected Ubuntu 20.04 LTS and\nUbuntu 22.04 LTS. (CVE-2022-23477, CVE-2022-23493)\n\nIt was discovered that xrdp incorrectly handled validation of\nclient-supplied data, which could lead to out-of-bounds writes. An attacker\ncould possibly use this issue to cause memory corruption or execute\narbitrary code. This issue only affected Ubuntu 20.04 LTS and\nUbuntu 22.04 LTS. (CVE-2022-23478)\n\nIt was discovered that xrdp incorrectly handled validation of\nclient-supplied data, which could lead to out-of-bounds reads. An attacker\ncould possibly use this issue to crash the program or extract sensitive\ninformation. This issue only affected Ubuntu 22.04 LTS. (CVE-2022-23613)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"xrdp","version":"0.9.5-2ubuntu0.1~esm2","description":"Remote Desktop Protocol (RDP) server","is_source":true},{"name":"xorgxrdp","version":"0.9.5-2ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-apps"},{"name":"xrdp","version":"0.9.5-2ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-apps"},{"name":"xrdp-pulseaudio-installer","version":"0.9.5-2ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"xrdp","version":"0.9.12-1ubuntu0.1+esm1","description":"Remote Desktop Protocol (RDP) server","is_source":true},{"name":"xrdp","version":"0.9.12-1ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-apps"}],"jammy":[{"name":"xrdp","version":"0.9.17-2ubuntu2+esm1","description":"Remote Desktop Protocol (RDP) server","is_source":true},{"name":"xrdp","version":"0.9.17-2ubuntu2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-apps"}],"trusty":[{"name":"xrdp","version":"0.6.0-1ubuntu0.1+esm3","description":"Remote Desktop Protocol (RDP) server","is_source":true},{"name":"xrdp","version":"0.6.0-1ubuntu0.1+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-infra"}],"xenial":[{"name":"xrdp","version":"0.6.1-2ubuntu0.3+esm3","description":"Remote Desktop Protocol (RDP) server","is_source":true},{"name":"xrdp","version":"0.6.1-2ubuntu0.3+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2022-23468","CVE-2022-23477","CVE-2022-23479","CVE-2022-23484","CVE-2022-23481","CVE-2022-23613","CVE-2022-23493","CVE-2022-23480","CVE-2022-23483","CVE-2022-23478","CVE-2023-42822","CVE-2022-23482","CVE-2023-40184"]}]},{"id":"CVE-2022-23468","published":"2022-12-09T18:15:00","updated_at":"2025-08-04T18:49:19.269793+00:00","description":"\nxrdp is an open source project which provides a graphical login to remote\nmachines using Microsoft Remote Desktop Protocol (RDP).\nxrdp < v0.9.21 contain a buffer over flow in xrdp_login_wnd_create()\nfunction. There are no known workarounds for this issue. Users are advised\nto upgrade.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-8c2f-mw8m-qpx6","https://ubuntu.com/security/notices/USN-6474-1","https://www.cve.org/CVERecord?id=CVE-2022-23468"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1025879"],"patches":{"xrdp":[]},"tags":{},"packages":[{"name":"xrdp","source":"https://ubuntu.com/security/cve?package=xrdp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xrdp","debian":"https://tracker.debian.org/pkg/xrdp","statuses":[{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.9.21","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"0.9.5-2ubuntu0.1~esm2","component":null,"pocket":"esm-apps"},{"release_codename":"focal","status":"released","description":"0.9.12-1ubuntu0.1+esm1","component":null,"pocket":"esm-apps"},{"release_codename":"jammy","status":"released","description":"0.9.17-2ubuntu2+esm1","component":null,"pocket":"esm-apps"},{"release_codename":"noble","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"0.9.21.1-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-6474-1"],"notices":[{"id":"USN-6474-1","title":"xrdp vulnerabilities","summary":"Several security issues were fixed in xrdp.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2023-11-08T13:47:00.462142","description":"It was discovered that xrdp incorrectly handled validation of\nclient-supplied data, which could lead to out-of-bounds reads. An attacker\ncould possibly use this issue to crash the program or extract sensitive\ninformation. (CVE-2022-23479, CVE-2022-23481, CVE-2022-23483,\nCVE-2023-42822)\n\nIt was discovered that xrdp improperly handled session establishment\nerrors. An attacker could potentially use this issue to bypass the\nOS-level session restrictions by PAM. (CVE-2023-40184)\n\nIt was discovered that xrdp incorrectly handled validation of\nclient-supplied data, which could lead to out-of-bounds writes. An attacker\ncould possibly use this issue to cause memory corruption or execute\narbitrary code. This issue only affected Ubuntu 18.04 LTS,\nUbuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2022-23468)\n\nIt was discovered that xrdp incorrectly handled validation of\nclient-supplied data, which could lead to out-of-bounds reads. An attacker\ncould possibly use this issue to crash the program or extract sensitive\ninformation. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS\nand Ubuntu 22.04 LTS. (CVE-2022-23480, CVE-2022-23482, CVE-2022-23484)\n\nIt was discovered that xrdp incorrectly handled validation of\nclient-supplied data, which could lead to out-of-bounds reads. An attacker\ncould possibly use this issue to crash the program or extract sensitive\ninformation. This issue only affected Ubuntu 20.04 LTS and\nUbuntu 22.04 LTS. (CVE-2022-23477, CVE-2022-23493)\n\nIt was discovered that xrdp incorrectly handled validation of\nclient-supplied data, which could lead to out-of-bounds writes. An attacker\ncould possibly use this issue to cause memory corruption or execute\narbitrary code. This issue only affected Ubuntu 20.04 LTS and\nUbuntu 22.04 LTS. (CVE-2022-23478)\n\nIt was discovered that xrdp incorrectly handled validation of\nclient-supplied data, which could lead to out-of-bounds reads. An attacker\ncould possibly use this issue to crash the program or extract sensitive\ninformation. This issue only affected Ubuntu 22.04 LTS. (CVE-2022-23613)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"xrdp","version":"0.9.5-2ubuntu0.1~esm2","description":"Remote Desktop Protocol (RDP) server","is_source":true},{"name":"xorgxrdp","version":"0.9.5-2ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-apps"},{"name":"xrdp","version":"0.9.5-2ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-apps"},{"name":"xrdp-pulseaudio-installer","version":"0.9.5-2ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"xrdp","version":"0.9.12-1ubuntu0.1+esm1","description":"Remote Desktop Protocol (RDP) server","is_source":true},{"name":"xrdp","version":"0.9.12-1ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-apps"}],"jammy":[{"name":"xrdp","version":"0.9.17-2ubuntu2+esm1","description":"Remote Desktop Protocol (RDP) server","is_source":true},{"name":"xrdp","version":"0.9.17-2ubuntu2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-apps"}],"trusty":[{"name":"xrdp","version":"0.6.0-1ubuntu0.1+esm3","description":"Remote Desktop Protocol (RDP) server","is_source":true},{"name":"xrdp","version":"0.6.0-1ubuntu0.1+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-infra"}],"xenial":[{"name":"xrdp","version":"0.6.1-2ubuntu0.3+esm3","description":"Remote Desktop Protocol (RDP) server","is_source":true},{"name":"xrdp","version":"0.6.1-2ubuntu0.3+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2022-23468","CVE-2022-23477","CVE-2022-23479","CVE-2022-23484","CVE-2022-23481","CVE-2022-23613","CVE-2022-23493","CVE-2022-23480","CVE-2022-23483","CVE-2022-23478","CVE-2023-42822","CVE-2022-23482","CVE-2023-40184"]}]},{"id":"CVE-2022-23494","published":"2022-12-08T22:15:00","updated_at":"2025-08-26T12:42:58.636931+00:00","description":"\ntinymce is an open source rich text editor. A cross-site scripting (XSS)\nvulnerability was discovered in the alert and confirm dialogs when these\ndialogs were provided with malicious HTML content. This can occur in\nplugins that use the alert or confirm dialogs, such as in the `image`\nplugin, which presents these dialogs when certain errors occur. The\nvulnerability allowed arbitrary JavaScript execution when an alert\npresented in the TinyMCE UI for the current user. This vulnerability has\nbeen patched in TinyMCE 5.10.7 and TinyMCE 6.3.1 by ensuring HTML\nsanitization was still performed after unwrapping invalid elements. Users\nare advised to upgrade to either 5.10.7 or 6.3.1. Users unable to upgrade\nmay ensure the the `images_upload_handler` returns a valid value as per the\nimages_upload_handler documentation.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/tinymce/tinymce/commit/6923d85eba6de3e08ebc9c5a387b5abdaa21150e","https://www.tiny.cloud/docs/tinymce/6/file-image-upload/#images_upload_handler","https://www.tiny.cloud/docs/release-notes/release-notes5107/#securityfixes","https://github.com/tinymce/tinymce/commit/8bb2d2646d4e1a718fce61a775fa22e9d317b32d","https://github.com/tinymce/tinymce/security/advisories/GHSA-gg8r-xjwq-4w92","https://www.tiny.cloud/docs/tinymce/6/6.3-release-notes/#security-fixes","https://www.cve.org/CVERecord?id=CVE-2022-23494"],"bugs":[""],"patches":{"tinymce":[]},"tags":{},"packages":[{"name":"tinymce","source":"https://ubuntu.com/security/cve?package=tinymce","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tinymce","debian":"https://tracker.debian.org/pkg/tinymce","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":36320,"limit":20,"total_results":79316}