CVE-2020-4044: Backport for 20.04-LTS

Bug #1954639 reported by Florian Bergmann
10
This bug affects 2 people
Affects Status Importance Assigned to Milestone
xrdp (Ubuntu)
Confirmed
Undecided
Unassigned

Bug Description

Hello,

We are using Ubuntu 20.04 LTS on our Servers with RDP access through XRDP.

We found out via vulnurability scanning that the CVE CVE-2020-4044 is still open in the LTS version.

In Debian the bug is already fixed in all codestreams: https://security-tracker.debian.org/tracker/CVE-2020-4044

Is there any news when or if the bugfix will be release to the LTS release 20.04 - I can see the same package version is already updated for 21.04.

lsb-release -rd

Description: Ubuntu 20.04.3 LTS
Release: 20.04

apt show xrdp
Package: xrdp
Version: 0.9.12-1

Thank you very much for the great work on Ubuntu and for any information regarding this issue.

CVE References

description: updated
description: updated
description: updated
summary: - CVE-2020-4044
+ CVE-2020-4044: Backport for 20.04-LTS
Revision history for this message
Launchpad Janitor (janitor) wrote :

Status changed to 'Confirmed' because the bug affects multiple users.

Changed in xrdp (Ubuntu):
status: New → Confirmed
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.