Linux Compatible
  • News
    • Channels
    • Archive
    • Search
    • Submit
  • Articles
    • Categories
  • Knowledgebase
  • Compatibility
    • Search
  • Links
  • Forums
  • Twitter
Advertisement

Latest News
[ Windows | Linux | Apple ]

· Microsoft Office Clone Updates Interface, Improves File Support
· Windows Firewall Control 4.0.0.0 released
· 10 amazing Linux desktop environments you've probably never seen
· Microsoft Office security flaw hits thousands in latest hacker attack
· Kubuntu 13.04 Raring Ringtail Review
· Windows Mobile 7 concept video shows why Microsoft dumped the platform
· Building a Thin Mini-ITX PC and more
· Microsoft wants consumers to control the camera by voice, according to filed patent
· Dell replays Windows 8 blame card as PC sales slide
· m23 rock 13.1 released

Upcoming News
· [RHSA-2013:0841-01] Important: kernel security update
· [RHSA-2013:0829-01] Important: kernel-rt security and bug fix update
· [RHSA-2013:0840-01] Important: kernel security update
· A4Tech Bloody Gun3 UC3 Headshot V8 Gaming Mouse Review - $40?= For The Ultimate Package
· Win a Kingston HyperX Beast 16GB 2133MHz Memory Kit @ Bigbruin.com
· HOT Raspberry Pi - A DIY Mini Desktop PC Build Project
· Seagate 600 Pro SSD Review (400GB) - Better Warranty, ?= 28% OP and Power Loss Protection
· REVIEW: PowerColor 7790 Turbo Duo @ PureOverclock
· MSI Z77A-GD65 Gaming Series Motherboard Review @ Legit Reviews
· Cooltek Coolcube Maxi Black @ techPowerUp

Linux Compatibility
· Dell Dimension 9100
· CL-CAM50001 UPC=3700284609322
· DFE 520 TX
· nVidia GeForce4 MX 440
· Gore: Ultimate Soldier
· SMC2802W V2 wi-fi 54Mbps PCI card
· Wireless modem router N300
· Dell P780
· ASUS A7V8X
· BricsCAD for Linux

New Forum Topics
· shutdown link ?
by: estirwent
on: 2013-05-11 17:46
18 replies, 6360 views

· Laptop keyboard drank soda
by: Zenn
on: 2013-04-30 00:27
1 replies, 649 views

· connecting to to internet with ubuntu
by: Zenn
on: 2013-04-30 00:26
2 replies, 4510 views

· Need Linux-compatible PS/2 expansion card
by: Zenn
on: 2013-04-30 00:26
1 replies, 713 views

· irql_not_less_or_equal blue screen
by: Zenn
on: 2013-04-30 00:25
2 replies, 1104 views

News Channels
· Drivers
· Guides
· Reviews
· Security
· Software
· Press Release
· Updates
· Interviews
· Linux
· General
· Debian
· Red Hat
· Slackware
· Gentoo
· Mandriva
· White Box
· SUSE
· GNOME
· KDE
· CentOS
· Ubuntu
· MEPIS
· Android

What's New
Login to see an overview of all news stories since your last visit.

Welcome to our website

To take full advantage of all features you need to login or register. Registration is completely free and takes only a few seconds.

Linux Compatible » News » September 2008 » USN-646-1: rdesktop vulnerabilities

USN-646-1: rdesktop vulnerabilities

Posted by Bob on: 09/19/2008 04:30 AM [ Print | 0 comment(s) ]

A new rdesktop vulnerabilities update is available for Ubuntu Linux. Here the announcement:




Ubuntu Security Notice USN-646-1 September 18, 2008
rdesktop vulnerabilities
CVE-2008-1801, CVE-2008-1802, CVE-2008-1803
==========================
==========================
=========

A security issue affects the following Ubuntu releases:

Ubuntu 6.06 LTS
Ubuntu 7.04
Ubuntu 7.10
Ubuntu 8.04 LTS

This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 6.06 LTS:
rdesktop 1.4.1-1.1ubuntu0.6.06.1

Ubuntu 7.04:
rdesktop 1.5.0-1ubuntu1.1

Ubuntu 7.10:
rdesktop 1.5.0-2ubuntu0.1

Ubuntu 8.04 LTS:
rdesktop 1.5.0-3+cvs20071006ubuntu0.1

In general, a standard system upgrade is sufficient to effect the
necessary changes.

Details follow:

It was discovered that rdesktop did not properly validate the length
of packet headers when processing RDP requests. If a user were tricked
into connecting to a malicious server, an attacker could cause a
denial of service or possible execute arbitrary code with the
privileges of the user. (CVE-2008-1801)

Multiple buffer overflows were discovered in rdesktop when processing
RDP redirect requests. If a user were tricked into connecting to a
malicious server, an attacker could cause a denial of service or
possible execute arbitrary code with the privileges of the user.
(CVE-2008-1802)

It was discovered that rdesktop performed a signed integer comparison
when reallocating dynamic buffers which could result in a heap-based
overflow. If a user were tricked into connecting to a malicious
server, an attacker could cause a denial of service or possible
execute arbitrary code with the privileges of the user.
(CVE-2008-1802)


Updated packages for Ubuntu 6.06 LTS:

Source archives:

http://security.ubuntu.com/ubuntu/pool/main/r/rdesktop/rdesktop_1.4.1-1=
.1ubuntu0.6.06.1.diff.gz
Size/MD5: 11833 02d252fcd49c4645b3e716d856d1c415
http://security.ubuntu.com/ubuntu/pool/main/r/rdesktop/rdesktop_1.4.1-1=
.1ubuntu0.6.06.1.dsc
Size/MD5: 652 ef3291adc58f0a7cb13a611b4f0a2121
http://security.ubuntu.com/ubuntu/pool/main/r/rdesktop/rdesktop_1.4.1.o=
rig.tar.gz
Size/MD5: 218413 ce6b2369d633128ff00a2a8ae7c18ef8

amd64 architecture (Athlon64, Opteron, EM64T Xeon):

http://security.ubuntu.com/ubuntu/pool/main/r/rdesktop/rdesktop_1.4.1-1=
.1ubuntu0.6.06.1_amd64.deb
Size/MD5: 111972 aa37f6bbd6e6aef1c522fbdb856b0f88

i386 architecture (x86 compatible Intel/AMD):

http://security.ubuntu.com/ubuntu/pool/main/r/rdesktop/rdesktop_1.4.1-1=
.1ubuntu0.6.06.1_i386.deb
Size/MD5: 101116 c763412c9df04d92d96ac35d3b1da461

powerpc architecture (Apple Macintosh G3/G4/G5):

http://security.ubuntu.com/ubuntu/pool/main/r/rdesktop/rdesktop_1.4.1-1=
.1ubuntu0.6.06.1_powerpc.deb
Size/MD5: 119686 a04bf8dfa52a4b9345c0768174c4fe5f

sparc architecture (Sun SPARC/UltraSPARC):

http://security.ubuntu.com/ubuntu/pool/main/r/rdesktop/rdesktop_1.4.1-1=
.1ubuntu0.6.06.1_sparc.deb
Size/MD5: 108374 f93183194eb83d0d303bc198260f5aaf

Updated packages for Ubuntu 7.04:

Source archives:

http://security.ubuntu.com/ubuntu/pool/main/r/rdesktop/rdesktop_1.5.0-1=
ubuntu1.1.diff.gz
Size/MD5: 20640 935bc4696bd2aea80b00ce2d1541b8a1
http://security.ubuntu.com/ubuntu/pool/main/r/rdesktop/rdesktop_1.5.0-1=
ubuntu1.1.dsc
Size/MD5: 648 fa4980e269f93cdc5fe4547b4ba270c6
http://security.ubuntu.com/ubuntu/pool/main/r/rdesktop/rdesktop_1.5.0.o=
rig.tar.gz
Size/MD5: 245137 433546f60fc0f201e99307ba188369ed

amd64 architecture (Athlon64, Opteron, EM64T Xeon):

http://security.ubuntu.com/ubuntu/pool/main/r/rdesktop/rdesktop_1.5.0-1=
ubuntu1.1_amd64.deb
Size/MD5: 138228 051403b954434d9f3abdeeeaf598ab6b

i386 architecture (x86 compatible Intel/AMD):

http://security.ubuntu.com/ubuntu/pool/main/r/rdesktop/rdesktop_1.5.0-1=
ubuntu1.1_i386.deb
Size/MD5: 122622 ddd936f095eca9f9c1ebaa9b2a1ac637

powerpc architecture (Apple Macintosh G3/G4/G5):

http://security.ubuntu.com/ubuntu/pool/main/r/rdesktop/rdesktop_1.5.0-1=
ubuntu1.1_powerpc.deb
Size/MD5: 147290 477231f887705ee5f5303d9d95c9b63f

sparc architecture (Sun SPARC/UltraSPARC):

http://security.ubuntu.com/ubuntu/pool/main/r/rdesktop/rdesktop_1.5.0-1=
ubuntu1.1_sparc.deb
Size/MD5: 131252 66fe53989b7540f8de5267e543fabb4e

Updated packages for Ubuntu 7.10:

Source archives:

http://security.ubuntu.com/ubuntu/pool/main/r/rdesktop/rdesktop_1.5.0-2=
ubuntu0.1.diff.gz
Size/MD5: 20644 87afc1c27f2489d0a7ce4d1592f294d6
http://security.ubuntu.com/ubuntu/pool/main/r/rdesktop/rdesktop_1.5.0-2=
ubuntu0.1.dsc
Size/MD5: 648 6bd1addbc212ec9b4f331be244e604aa
http://security.ubuntu.com/ubuntu/pool/main/r/rdesktop/rdesktop_1.5.0.o=
rig.tar.gz
Size/MD5: 245137 433546f60fc0f201e99307ba188369ed

amd64 architecture (Athlon64, Opteron, EM64T Xeon):

http://security.ubuntu.com/ubuntu/pool/main/r/rdesktop/rdesktop_1.5.0-2=
ubuntu0.1_amd64.deb
Size/MD5: 138036 4a7e96222fe9027700e816acf59bb734

i386 architecture (x86 compatible Intel/AMD):

http://security.ubuntu.com/ubuntu/pool/main/r/rdesktop/rdesktop_1.5.0-2=
ubuntu0.1_i386.deb
Size/MD5: 122472 b1dd9c0cb2641891ddcfec99704b46a9

lpia architecture (Low Power Intel Architecture):

http://ports.ubuntu.com/pool/main/r/rdesktop/rdesktop_1.5.0-2ubuntu0.1_=
lpia.deb
Size/MD5: 122174 ddcb80d1456ba036a283bd239e5d559b

powerpc architecture (Apple Macintosh G3/G4/G5):

http://security.ubuntu.com/ubuntu/pool/main/r/rdesktop/rdesktop_1.5.0-2=
ubuntu0.1_powerpc.deb
Size/MD5: 146892 09c1dda0b426d812b867f311884854cc

sparc architecture (Sun SPARC/UltraSPARC):

http://security.ubuntu.com/ubuntu/pool/main/r/rdesktop/rdesktop_1.5.0-2=
ubuntu0.1_sparc.deb
Size/MD5: 130926 4c438675fae5796dc90d18c38b09993f

Updated packages for Ubuntu 8.04 LTS:

Source archives:

http://security.ubuntu.com/ubuntu/pool/main/r/rdesktop/rdesktop_1.5.0-3=
+cvs20071006ubuntu0.1.diff.gz
Size/MD5: 239616 dd50827c7f209fba8acce7438046a0c5
http://security.ubuntu.com/ubuntu/pool/main/r/rdesktop/rdesktop_1.5.0-3=
+cvs20071006ubuntu0.1.dsc
Size/MD5: 673 df18cff01658e869689437b0f4ba6a3f
http://security.ubuntu.com/ubuntu/pool/main/r/rdesktop/rdesktop_1.5.0.o=
rig.tar.gz
Size/MD5: 245137 433546f60fc0f201e99307ba188369ed

amd64 architecture (Athlon64, Opteron, EM64T Xeon):

http://security.ubuntu.com/ubuntu/pool/main/r/rdesktop/rdesktop_1.5.0-3=
+cvs20071006ubuntu0.1_amd64.deb
Size/MD5: 146160 553eebe2e4574d5ecfca06471fc5f765

i386 architecture (x86 compatible Intel/AMD):

http://security.ubuntu.com/ubuntu/pool/main/r/rdesktop/rdesktop_1.5.0-3=
+cvs20071006ubuntu0.1_i386.deb
Size/MD5: 128674 9bc9f5f95fd66bf57b0520299e478b08

lpia architecture (Low Power Intel Architecture):

http://ports.ubuntu.com/pool/main/r/rdesktop/rdesktop_1.5.0-3+cvs200710=
06ubuntu0.1_lpia.deb
Size/MD5: 129648 abdab7d9e099f1d6dde38c7e4efe4707

powerpc architecture (Apple Macintosh G3/G4/G5):

http://ports.ubuntu.com/pool/main/r/rdesktop/rdesktop_1.5.0-3+cvs200710=
06ubuntu0.1_powerpc.deb
Size/MD5: 152548 25633e850f1523be7b76a08e2ff33543

sparc architecture (Sun SPARC/UltraSPARC):

http://ports.ubuntu.com/pool/main/r/rdesktop/rdesktop_1.5.0-3+cvs200710=
06ubuntu0.1_sparc.deb
Size/MD5: 136268 1cd132a6dc1d34fc08df8a87ea559c6f



--Y7xTucakfITjPcLV
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: Digital signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)

iD8DBQFI0rGhW0JvuRdL8BoRAmHWAKCDj0NPFz3By6oadymSN48L6aQL6QCbB1Zy
zxcbL8ciNA/h3dR+gBkR/6s=
=uakK
-----END PGP SIGNATURE-----


Bookmark and Share

« deVault Pro 2009 R3.2 · HS WinPerfect 6.18 »

Linux Compatible » News » September 2008 » USN-646-1: rdesktop vulnerabilities
All products mentioned are registered trademarks or trademarks of their respective owners.
© 2002-2013 Esselbach Internet Solutions - All Rights Reserved. Terms and privacy policy
Powered by Contentteller® Business Edition