← Back

CVE-2017-16927

nvd nist
Published: Nov 23, 2017Modified: May 13, 2026

JSON object

Loading...
8.4
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.5 / Impact: 5.9
Source: NVD

Description

The scp_v0s_accept function in sesman/libscp/libscp_v0.c in the session manager in xrdp through 0.9.4 uses an untrusted integer as a write length, which allows local users to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted input stream.

Affected (2)

1 product
Xrdp
1 product
Debian Linux
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 0.9.4
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 7.0

References (6)

Timeline

No history available yet.