metalefty
2c2eff3b59
Merge commit from fork
...
CVE-2026-55639: OOB read in GCC Conference Create Request
2026-07-02 17:09:54 +09:00
metalefty
0aae834802
Merge commit from fork
...
CVE-2026-55645: OOB read in Client Control PDU processing
2026-07-02 16:57:51 +09:00
metalefty
0af3b1ecf8
Merge commit from fork
...
CVE-2026-44978: Check FIPS PDU padding value before use
2026-07-01 17:56:20 +09:00
metalefty
b3e1a5f17d
Merge commit from fork
...
CVE-2026-55238: Possible OOB reads in capability processing
2026-07-01 17:45:49 +09:00
metalefty
9627823a1b
Merge commit from fork
...
CVE-2026-55626: Disable Xvnc TCP listning in UDS mode
2026-07-01 08:51:16 +09:00
Koichiro Iwao
f76a30b577
CVE-2026-55626: Disable Xvnc TCP listning in UDS mode
2026-06-24 08:42:09 +09:00
matt335672
492bd7ed4d
Merge pull request #3813 from matt335672/update_librfxcodec
...
librfxcodec: Update to latest version in devel
2026-06-23 09:45:17 +01:00
matt335672
fea7f56280
librfxcodec: Update to latest version in devel
...
Adds these changes to the librfxcodec in devel
- 637ffa28 remove some noisy logging on startup
- 1b6c8f5a fixed constVariablePointer Cppcheck warnings
- 0f10c695 always use if-else chain for RFX_USE_ACCEL_* preprocessor checks
- 3c0d7c49 rfxencode_rgb_to_yuv.c: removed some unnecessary return values
2026-06-23 09:27:21 +01:00
matt335672
21d38d0c1e
Merge pull request #3811 from matt335672/fix_cve_2026_42218_regression
...
sesexec: Fix CVE-2026-42218 regression
2026-06-17 10:08:51 +01:00
matt335672
d4d20fc82d
sesexec: Fix CVE-2026-42218 regression
...
cppcheck has picked up on the use of an unitialised variable in
the implementation of the fix for CVE-2026-42218
2026-06-17 09:54:06 +01:00
matt335672
6cb996e355
Merge pull request #3698 from lcniel/enable_token_with_auto_logon
...
Allow username-affixed token to be used with INFO_AUTOLOGON flag set in client
2026-06-17 09:36:43 +01:00
matt335672
4aa8bdf1ea
CVE-2026-55238: Possible OOB reads in capability processing
...
Add missing per-capability length checks in the RDP Confirm Active PDU
parser, and abort the parser if a buffer length violation is discovered.
2026-06-17 09:22:05 +01:00
matt335672
9d16ec4e75
CVE-2026-55639: OOB read in GCC Conference Create Request
2026-06-17 09:18:20 +01:00
matt335672
b1edb60c1d
CVE-2026-55645: OOB read in Client Control PDU processing
2026-06-17 09:14:18 +01:00
metalefty
c56a3ea202
Merge commit from fork
...
CVE-2026-42218: Ensure auth fails take a fixed time
2026-06-15 15:40:24 +09:00
Leonard Nielsen
40c1a316f4
Allow for token logon even with INFO_AUTOLOGON flag set
2026-06-11 14:40:59 +02:00
matt335672
e42951868b
CVE-2026-44978: Check FIPS PDU padding value before use
2026-05-11 10:46:50 +01:00
metalefty
c8cd758283
Merge pull request #3798 from metalefty/freebsd-ci
...
CI: Switch FreeBSD CI from Cirrus CI to GitHub Actions
2026-04-29 00:36:02 +09:00
Koichiro Iwao
ad6c210c2b
CI: Run FreeBSD CI via GitHub Actions
...
Resolves: #3797
2026-04-28 11:47:13 +09:00
Koichiro Iwao
e6f350ae1a
CI: Remove Cirrus CI as the service is shutting down
2026-04-28 11:45:25 +09:00
matt335672
07479384a6
CVE-2026-42218: Ensure auth fails take a fixed time
...
Implement a constant time for password-based authentication failure.
2026-04-27 10:29:12 +01:00
matt335672
102da4f42b
Merge pull request #3792 from matt335672/sig_fix
...
regression: Fix SEGV in xrdp when running over TLS
2026-04-20 13:47:22 +01:00
matt335672
5fa4dc02bc
regression: Fix SEGV in xrdp when running over TLS
...
When not using classic RDP encryption, an uninitialsed pointer can be
passed to sig64_to_uint64() in development mode.
2026-04-20 13:34:09 +01:00
matt335672
0005893a93
Merge pull request #3681 from firewave/cppcheck-performance
...
enabled cppcheck `performance` checks
2026-04-17 16:26:20 +01:00
firewave
0410abef98
enabled cppcheck performance checks
2026-04-17 15:07:58 +02:00
metalefty
f6d3d12137
Merge pull request #3787 from metalefty/security
...
Clarify handling of duplicate vulnerability reports
2026-04-17 21:53:46 +09:00
Koichiro Iwao
3610afd52b
Clarify handling of duplicate vulnerability reports
2026-04-17 21:10:26 +09:00
matt335672
43fa055ec4
Merge pull request #3786 from matt335672/remove_ulalaca
...
ulalaca: Remove for now
2026-04-17 12:46:33 +01:00
matt335672
800b5f5e7c
ulalaca: Remove for now
...
The ulalaca module for Mac is suffering from a lack of maintenance
currently, and its inclusion is holding up the introduction of some
code quality changes. This PR removes the module for now.
2026-04-17 12:23:17 +01:00
metalefty
41f6e6b995
Merge pull request #3782 from metalefty/cifix
...
Supress -Wunused-function warnings
2026-04-16 07:34:23 +09:00
Koichiro Iwao
5e7a7c046d
Supress -Wunused-function warnings
...
`sig64_to_uint64()` is only called when devel logging is enabled.
Guard the function with USE_DEVEL_LOGGING macro.
2026-04-15 21:13:29 +09:00
metalefty
c3788a374a
Merge commit from fork
...
security: Exit on failure of env_set_user()
2026-04-14 20:39:42 +09:00
matt335672
53bc57cf59
security: Exit on failure of env_set_user()
...
CVE-2026-32107. Prevent possible privilege escalation if setuid()
fails.
2026-04-14 11:52:28 +01:00
metalefty
7738d111d5
Merge commit from fork
...
CVE-2026-35512: Heap overflow in dynvc processing
2026-04-14 17:00:20 +09:00
metalefty
084eb2237e
Merge commit from fork
...
CVE-2026-33689: Fix length check on channel open
2026-04-14 16:43:27 +09:00
metalefty
2e465c0b3a
Merge commit from fork
...
CVE-2026-33145: Default AllowAlternateShell to 'no'
2026-04-14 15:14:20 +09:00
metalefty
16c971a437
Merge commit from fork
...
security: vulns in neutrinordp fragment reassembly
2026-04-14 15:07:03 +09:00
metalefty
6d1f89a919
Merge commit from fork
...
CVE-2026-33516 : Address potential OOB read
2026-04-14 15:01:23 +09:00
metalefty
1bacf22fb7
Merge commit from fork
...
Check HMAC values when non-TLS connections are used
2026-04-14 14:06:45 +09:00
metalefty
220a50b1d2
Merge commit from fork
...
CVE-2026-32624: buffer overflow if domain sep used
2026-04-14 09:30:27 +09:00
jsorg71
832edcab20
Merge pull request #3779 from jsorg71/instfiles_err
...
remove keymap file before creating sym link
2026-04-06 12:05:57 -07:00
Jay Sorg
05210adb22
use -f when creating sym link
2026-04-06 10:29:17 -07:00
matt335672
99dfacfffc
Merge pull request #3755 from matt335672/gfx_resize
...
resizing: Simplify GFX resizing
2026-04-06 12:46:46 +01:00
matt335672
41a4af0a36
CVE-2026-35512: Heap overflow in dynvc processing
...
Length checking for the EGFX dynamic virtual channel is inadequate,
allowing for heap overflows to be forced by a malicious client before
authentication.
2026-04-06 12:39:32 +01:00
matt335672
6831249bed
CVE-2026-33516 : Address potential OOB read
...
The codec list processing code contains a potential out-of-bounds
read, as the length check comes after the data is read.
2026-04-02 11:23:42 +01:00
matt335672
8e5875e438
Merge pull request #3777 from gpotter2/rename-rdpflags
...
Rename RDP_INFO flags to spec names
2026-04-01 09:17:57 +01:00
gpotter2
42b830f124
Rename RDP_INFO flags to spec names, add missing
2026-03-31 21:22:33 +02:00
matt335672
36fbebcb9d
Merge pull request #3768 from matt335672/remove_unused_auth
...
sesman: Remove unused authentication methods
2026-03-26 17:55:48 +00:00
matt335672
1f34c4b37c
Merge pull request #3767 from Kropyls/devel
...
g_tcp_connect ipv4/6 mixing fix
2026-03-23 18:23:10 +00:00
matt335672
3c131a9f5e
CVE-2026-33689: Fix length check on channel open
...
A check for at least two bytes remaining in a buffer should be 4 bytes.
2026-03-23 17:38:38 +00:00