CVE
- Id
- 103787
- CVE No.
- CVE-2017-6967
- Status
- Candidate
- Description
- xrdp 0.9.1 calls the PAM function auth_start_session() in an incorrect location, leading to PAM session modules not being properly initialized, with a potential consequence of incorrect configurations or elevation of privileges, aka a pam_limits.so bypass.
- Phase
- Assigned (20170317)
- Votes
- None (candidate not yet proposed)
- Comments