Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 602764 (CVE-2013-1430)

Summary: net-misc/xrdp: Cleartext password shown in file after logging into xrdp session
Product: Gentoo Security Reporter: Agostino Sarubbo <ago>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: trivial CC: mgorny
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: https://bugzilla.redhat.com/show_bug.cgi?id=1404969
Whiteboard: ~3 [noglsa/cve]
Package list:
Runtime testing required: ---
Bug Depends on: 607096    
Bug Blocks:    

Description Agostino Sarubbo gentoo-dev 2016-12-15 15:45:21 UTC
From ${URL} :

When successfully logging in using RDP into a xrdp session, the file
~/.vnc/sesman_${username}_passwd is created. Its content is the
equivalent of the users clear text password, DES encrypted with a known
key.

Upstream bug:

https://github.com/neutrinolabs/xrdp/pull/497


@maintainer(s): since the package or the affected version has never been marked as stable, we don't need to stabilize it. After the bump, please remove the affected versions from the tree.
Comment 1 Thomas Deutschmann (RETIRED) gentoo-dev 2017-01-09 00:52:35 UTC
@ Maintainer(s): Please bump to >=net-misc/xrdp-0.9.1
Comment 2 Matt Turner gentoo-dev 2017-02-25 20:45:52 UTC
x11rdp and xrdp are removed, per bug 607096. Presumably this can now be closed.
Comment 3 Yury German Gentoo Infrastructure gentoo-dev 2017-02-26 19:51:14 UTC
Thank you for your work.