FEDORA-2024-41c1bf8de6
Packages in this update:
xrdp-0.10.1-1.fc39
Update description:
Release notes for xrdp v0.10.1 (2024/07/31)
General announcements
A clipboard bugfix included in this release is sponsored by Krämer Pferdesport GmbH & Co KG. We very much appreciate the sponsorship.
Please consider sponsoring or making a donation to the project if you like xrdp. We accept financial contributions via Open Collective. Direct donations to each developer via GitHub Sponsors are also welcomed.
Security fixes
Unauthenticated RDP security scan finding / partial auth bypass (no CVE). Thanks to @txtdawg for reporting this.
New features
GFX-RFX lossy compression levels are now selectable depending on connection type on the client (#3183, backport of #2973)
Bug fixes
A regression in the code for creating the chansrv FUSE directory has been fixed (#3088, backport of #3082)
Fix a systemd dependency (“network-online.target”) (#3088, backport of #3086)
A problem in session list processing which could result in incorrect display assignments has been fixed (#3088, backport of #3103)
A problem in GFX resizing which could lead to a SEGV in xrdp has been fixed (#3088, backport of #3107)
A problem with the US Dvorak keyboard layout has been resolved (#3088, backport of #3112)
A regression bug when pasting image to LibreOffice has been fixed [Sponsored by Krämer Pferdesport GmbH & Co KG] (#3102 #3120)
Fix a regression when the server tries to negotiate GFX when max_bpp is not high enough (#3118 #3122)
Fix a GFX multi-monitor screen placing issue on minimise/maximize (#3075 #3127)
Fix an issue some files are not included properly in release tarball (#3149 #3150)
Using ‘I’ in the session selection policy now works correctly (#3167 #3171)
A potential name buffer overflow in the redirector has been fixed [no security implications] (#3175)
Screens wider than 4096 pixels should now be supported (#3083)
An unnecessary licensing exchange during connection setup has been removed. This was causing problems for FIPS-compliant clients (#3132 backport of #3143)
Internal changes
FreeBSD CI bumped to 13.3 (#3088, backport of #3104)
Changes for users
None since v0.10.0.
If moving from v0.9.x, read the v0.10.0 release note.
Changes for packagers or developers
None since v0.10.0.
If moving from v0.9.x, read the v0.10.0 release note.
More Stories
A Vulnerability in Apache Struts2 Could Allow for Remote Code Execution
A vulnerability has been discovered in Apache Struts2, which could allow for remote code execution. Apache Struts2 is an open-source...
CyberDanube Security Research 20241219-0 | Authenticated Remote Code Execution in Ewon Flexy 205
Posted by Thomas Weber | CyberDanube via Fulldisclosure on Dec 21 CyberDanube Security Research 20241219-0 ------------------------------------------------------------------------------- title| Authenticated Remote Code...
USN-7179-1: Linux kernel vulnerabilities
Andy Nguyen discovered that the Bluetooth L2CAP implementation in the Linux kernel contained a type-confusion error. A physically proximate remote...
USN-7173-2: Linux kernel vulnerabilities
Ziming Zhang discovered that the DRM driver for VMware Virtual GPU did not properly handle certain error conditions, leading to...
swiftlint-0.57.1-1.fc42
FEDORA-2024-87d30b4fbf Packages in this update: swiftlint-0.57.1-1.fc42 Update description: Automatic update for swiftlint-0.57.1-1.fc42. Changelog * Fri Dec 20 2024 Davide Cavalca...
USN-7166-3: Linux kernel (HWE) vulnerabilities
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This...