{"id":"MGASA-2021-0016","summary":"Updated xrdp packages fix security vulnerability","details":"Ashley Newson discovered that the XRDP sessions manager was susceptible to\ndenial of service. A local attacker can further take advantage of this flaw to\nimpersonate the XRDP sessions manager and capture any user credentials that are\nsubmitted to XRDP, approve or reject arbitrary login credentials or to hijack\nexisting sessions for xorgxrdp sessions (CVE-2020-4044).\n","modified":"2026-04-16T04:41:45.228547536Z","published":"2021-01-10T19:46:12Z","upstream":["CVE-2020-4044"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2021-0016.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=26931"},{"type":"WEB","url":"https://www.debian.org/security/2020/dsa-4737"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/7FYD6USHZXDI2EAZVGOVFMAE7ILP3SPL/"}],"affected":[{"package":{"name":"xrdp","ecosystem":"Mageia:7","purl":"pkg:rpm/mageia/xrdp?arch=source&distro=mageia-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.9.10-1.1.mga7"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2021-0016.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}