CVE-2008-5904

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
15/01/2009
Last modified:
09/04/2025

Description

The rdp_rdp_process_color_pointer_pdu function in rdp/rdp_rdp.c in xrdp 0.4.1 and earlier allows remote RDP servers to have an unknown impact via input data that sets crafted values for certain length variables, leading to a buffer overflow.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:xrdp:xrdp:*:*:*:*:*:*:*:* 0.4.1 (including)
cpe:2.3:a:xrdp:xrdp:0.3:*:*:*:*:*:*:*
cpe:2.3:a:xrdp:xrdp:0.3.1:*:*:*:*:*:*:*
cpe:2.3:a:xrdp:xrdp:0.3.2:*:*:*:*:*:*:*
cpe:2.3:a:xrdp:xrdp:0.4:*:*:*:*:*:*:*