Gentoo Archives: gentoo-announce

From: Aaron Bauman <bman@g.o>
To: gentoo-announce@l.g.o
Subject: [gentoo-announce] [ GLSA 201903-06 ] rdesktop: Multiple vulnerabilities
Date: Sun, 10 Mar 2019 20:50:09
Message-Id: 20190310204552.GE6348@monkey
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 201903-06
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 https://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: rdesktop: Multiple vulnerabilities
9 Date: March 10, 2019
10 Bugs: #674558
11 ID: 201903-06
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Multiple vulnerabilities have been discovered in rdesktop, the worst of
19 which could result in the remote execution of arbitrary code.
20
21 Background
22 ==========
23
24 rdesktop is a Remote Desktop Protocol (RDP) Client.
25
26 Affected packages
27 =================
28
29 -------------------------------------------------------------------
30 Package / Vulnerable / Unaffected
31 -------------------------------------------------------------------
32 1 net-misc/rdesktop < 1.8.4 >= 1.8.4
33
34 Description
35 ===========
36
37 Multiple vulnerabilities have been discovered in rdesktop. Please
38 review the CVE identifiers referenced below for details.
39
40 Impact
41 ======
42
43 A remote attacker could cause a Denial of Service condition, obtain
44 sensitive information, or execute arbitrary code.
45
46 Workaround
47 ==========
48
49 There is no known workaround at this time.
50
51 Resolution
52 ==========
53
54 All rdesktop users should upgrade to the latest version:
55
56 # emerge --sync
57 # emerge --ask --oneshot --verbose ">=net-misc/rdesktop-1.8.4"
58
59 References
60 ==========
61
62 [ 1 ] CVE-2018-20174
63 https://nvd.nist.gov/vuln/detail/CVE-2018-20174
64 [ 2 ] CVE-2018-20175
65 https://nvd.nist.gov/vuln/detail/CVE-2018-20175
66 [ 3 ] CVE-2018-20176
67 https://nvd.nist.gov/vuln/detail/CVE-2018-20176
68 [ 4 ] CVE-2018-20177
69 https://nvd.nist.gov/vuln/detail/CVE-2018-20177
70 [ 5 ] CVE-2018-20178
71 https://nvd.nist.gov/vuln/detail/CVE-2018-20178
72 [ 6 ] CVE-2018-20179
73 https://nvd.nist.gov/vuln/detail/CVE-2018-20179
74 [ 7 ] CVE-2018-20180
75 https://nvd.nist.gov/vuln/detail/CVE-2018-20180
76 [ 8 ] CVE-2018-20181
77 https://nvd.nist.gov/vuln/detail/CVE-2018-20181
78 [ 9 ] CVE-2018-20182
79 https://nvd.nist.gov/vuln/detail/CVE-2018-20182
80 [ 10 ] CVE-2018-8791
81 https://nvd.nist.gov/vuln/detail/CVE-2018-8791
82 [ 11 ] CVE-2018-8792
83 https://nvd.nist.gov/vuln/detail/CVE-2018-8792
84 [ 12 ] CVE-2018-8793
85 https://nvd.nist.gov/vuln/detail/CVE-2018-8793
86 [ 13 ] CVE-2018-8794
87 https://nvd.nist.gov/vuln/detail/CVE-2018-8794
88 [ 14 ] CVE-2018-8795
89 https://nvd.nist.gov/vuln/detail/CVE-2018-8795
90 [ 15 ] CVE-2018-8796
91 https://nvd.nist.gov/vuln/detail/CVE-2018-8796
92 [ 16 ] CVE-2018-8797
93 https://nvd.nist.gov/vuln/detail/CVE-2018-8797
94 [ 17 ] CVE-2018-8798
95 https://nvd.nist.gov/vuln/detail/CVE-2018-8798
96 [ 18 ] CVE-2018-8799
97 https://nvd.nist.gov/vuln/detail/CVE-2018-8799
98 [ 19 ] CVE-2018-8800
99 https://nvd.nist.gov/vuln/detail/CVE-2018-8800
100
101 Availability
102 ============
103
104 This GLSA and any updates to it are available for viewing at
105 the Gentoo Security Website:
106
107 https://security.gentoo.org/glsa/201903-06
108
109 Concerns?
110 =========
111
112 Security is a primary focus of Gentoo Linux and ensuring the
113 confidentiality and security of our users' machines is of utmost
114 importance to us. Any security concerns should be addressed to
115 security@g.o or alternatively, you may file a bug at
116 https://bugs.gentoo.org.
117
118 License
119 =======
120
121 Copyright 2019 Gentoo Foundation, Inc; referenced text
122 belongs to its owner(s).
123
124 The contents of this document are licensed under the
125 Creative Commons - Attribution / Share Alike license.
126
127 https://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature