FEDORA-EPEL-2023-6770a3482d
Packages in this update:
xrdp-0.9.23-1.el8
Update description:
Release notes for xrdp v0.9.23 (2023/08/31)
General announcements
Running xrdp and xrdp-sesman on separate hosts is still supported by this release, but is now deprecated. This is not secure. A future v1.0 release will replace the TCP socket used between these processes with a Unix Domain Socket, and then cross-host running will not be possible.
Security fixes
CVE-2023-40184: Improper handling of session establishment errors allows bypassing OS-level session restrictions (Reported by @gafusss)
Bug fixes
Environment variables set by PAM modules are no longer restricted to around 250 characters (#2712)
X11 clipboard clients now no longer hang when requesting a clipboard format which isn’t available (#2767)
New features
No new features in this release.
Internal changes
Introduce release tarball generation script (#2703)
cppcheck version used for CI bumped to 2.11 (#2738)
Known issues
On-the-fly resolution change requires the Microsoft Store version of Remote Desktop client but sometimes crashes on connect (#1869)
xrdp’s login dialog is not relocated at the center of the new resolution after on-the-fly resolution change happens (#1867)
More Stories
redis-7.2.7-1.fc40
FEDORA-2025-72fd0442cc Packages in this update: redis-7.2.7-1.fc40 Update description: Redis 7.2.7 Released Mon 6 Jan 2025 12:30:00 IDT Upgrade urgency SECURITY:...
USN-7159-5: Linux kernel (Raspberry Pi) vulnerabilities
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This...
USN-7154-2: Linux kernel (HWE) vulnerabilities
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This...
USN-7182-1: Ceph vulnerability
It was discovered that Ceph incorrectly handled unsupported JWT algorithms in the RadosGW gateway. An attacker could possibly use this...
USN-7181-1: Salt vulnerability
It was discovered that Salt incorrectly handled web requests when the SSH client was enabled. An attacker could possibly use...
USN-7180-1: Python vulnerabilities
It was discovered that Python incorrectly handled certain scripts. An attacker could possibly use this issue to execute arbitrary code...