Commit Graph

5337 Commits

Author SHA1 Message Date
metalefty 5642decb5f Merge commit from fork
CVE-2026-41521: lib_framebuffer_update int overflow
2026-07-02 17:24:29 +09:00
metalefty 4bf38e3d8e Merge commit from fork
CVE-2026-44178: Heap overflow in xrdp->chansrv msgs
2026-07-02 17:22:04 +09:00
metalefty 2c2eff3b59 Merge commit from fork
CVE-2026-55639: OOB read in GCC Conference Create Request
2026-07-02 17:09:54 +09:00
metalefty 0aae834802 Merge commit from fork
CVE-2026-55645: OOB read in Client Control PDU processing
2026-07-02 16:57:51 +09:00
metalefty 0af3b1ecf8 Merge commit from fork
CVE-2026-44978: Check FIPS PDU padding value before use
2026-07-01 17:56:20 +09:00
metalefty b3e1a5f17d Merge commit from fork
CVE-2026-55238: Possible OOB reads in capability processing
2026-07-01 17:45:49 +09:00
metalefty 9627823a1b Merge commit from fork
CVE-2026-55626: Disable Xvnc TCP listning in UDS mode
2026-07-01 08:51:16 +09:00
Koichiro Iwao f76a30b577 CVE-2026-55626: Disable Xvnc TCP listning in UDS mode 2026-06-24 08:42:09 +09:00
matt335672 492bd7ed4d Merge pull request #3813 from matt335672/update_librfxcodec
librfxcodec: Update to latest version in devel
2026-06-23 09:45:17 +01:00
matt335672 fea7f56280 librfxcodec: Update to latest version in devel
Adds these changes to the librfxcodec in devel
- 637ffa28 remove some noisy logging on startup
- 1b6c8f5a fixed constVariablePointer Cppcheck warnings
- 0f10c695 always use if-else chain for RFX_USE_ACCEL_* preprocessor checks
- 3c0d7c49 rfxencode_rgb_to_yuv.c: removed some unnecessary return values
2026-06-23 09:27:21 +01:00
matt335672 21d38d0c1e Merge pull request #3811 from matt335672/fix_cve_2026_42218_regression
sesexec: Fix CVE-2026-42218 regression
2026-06-17 10:08:51 +01:00
matt335672 d4d20fc82d sesexec: Fix CVE-2026-42218 regression
cppcheck has picked up on the use of an unitialised variable in
the implementation of the fix for CVE-2026-42218
2026-06-17 09:54:06 +01:00
matt335672 6cb996e355 Merge pull request #3698 from lcniel/enable_token_with_auto_logon
Allow username-affixed token to be used with INFO_AUTOLOGON flag set in client
2026-06-17 09:36:43 +01:00
matt335672 4aa8bdf1ea CVE-2026-55238: Possible OOB reads in capability processing
Add missing per-capability length checks in the RDP Confirm Active PDU
parser, and abort the parser if a buffer length violation is discovered.
2026-06-17 09:22:05 +01:00
matt335672 9d16ec4e75 CVE-2026-55639: OOB read in GCC Conference Create Request 2026-06-17 09:18:20 +01:00
matt335672 b1edb60c1d CVE-2026-55645: OOB read in Client Control PDU processing 2026-06-17 09:14:18 +01:00
metalefty c56a3ea202 Merge commit from fork
CVE-2026-42218: Ensure auth fails take a fixed time
2026-06-15 15:40:24 +09:00
Leonard Nielsen 40c1a316f4 Allow for token logon even with INFO_AUTOLOGON flag set 2026-06-11 14:40:59 +02:00
matt335672 f94ae70148 Use symbols for desktop size limits 2026-06-08 11:12:07 +01:00
matt335672 2a94fc9674 CVE-2026-41521: lib_framebuffer_update int overflow
An integer overflow can lead to possible heap info leak and ASLR
bypass.
2026-05-12 10:23:11 +01:00
matt335672 e42951868b CVE-2026-44978: Check FIPS PDU padding value before use 2026-05-11 10:46:50 +01:00
matt335672 3e39be9c8e CVE-2026-44178: Heap overflow in xrdp->chansrv msgs
Some xrdp -> chansrv messages allocate a fixed-size buffer which
can be overflowed by a malicious RDP client.
2026-05-06 10:32:39 +01:00
metalefty c8cd758283 Merge pull request #3798 from metalefty/freebsd-ci
CI: Switch FreeBSD CI from Cirrus CI to GitHub Actions
2026-04-29 00:36:02 +09:00
Koichiro Iwao ad6c210c2b CI: Run FreeBSD CI via GitHub Actions
Resolves:   #3797
2026-04-28 11:47:13 +09:00
Koichiro Iwao e6f350ae1a CI: Remove Cirrus CI as the service is shutting down 2026-04-28 11:45:25 +09:00
matt335672 07479384a6 CVE-2026-42218: Ensure auth fails take a fixed time
Implement a constant time for password-based authentication failure.
2026-04-27 10:29:12 +01:00
matt335672 102da4f42b Merge pull request #3792 from matt335672/sig_fix
regression: Fix SEGV in xrdp when running over TLS
2026-04-20 13:47:22 +01:00
matt335672 5fa4dc02bc regression: Fix SEGV in xrdp when running over TLS
When not using classic RDP encryption, an uninitialsed pointer can be
passed to sig64_to_uint64() in development mode.
2026-04-20 13:34:09 +01:00
matt335672 0005893a93 Merge pull request #3681 from firewave/cppcheck-performance
enabled cppcheck `performance` checks
2026-04-17 16:26:20 +01:00
firewave 0410abef98 enabled cppcheck performance checks 2026-04-17 15:07:58 +02:00
metalefty f6d3d12137 Merge pull request #3787 from metalefty/security
Clarify handling of duplicate vulnerability reports
2026-04-17 21:53:46 +09:00
Koichiro Iwao 3610afd52b Clarify handling of duplicate vulnerability reports 2026-04-17 21:10:26 +09:00
matt335672 43fa055ec4 Merge pull request #3786 from matt335672/remove_ulalaca
ulalaca: Remove for now
2026-04-17 12:46:33 +01:00
matt335672 800b5f5e7c ulalaca: Remove for now
The ulalaca module for Mac  is suffering from a lack of maintenance
currently, and its inclusion is holding up the introduction of some
code quality changes. This PR removes the module for now.
2026-04-17 12:23:17 +01:00
metalefty 41f6e6b995 Merge pull request #3782 from metalefty/cifix
Supress -Wunused-function warnings
2026-04-16 07:34:23 +09:00
Koichiro Iwao 5e7a7c046d Supress -Wunused-function warnings
`sig64_to_uint64()` is only called when devel logging is enabled.
Guard the function with USE_DEVEL_LOGGING macro.
2026-04-15 21:13:29 +09:00
metalefty c3788a374a Merge commit from fork
security: Exit on failure of env_set_user()
2026-04-14 20:39:42 +09:00
matt335672 53bc57cf59 security: Exit on failure of env_set_user()
CVE-2026-32107. Prevent possible privilege escalation if setuid()
fails.
2026-04-14 11:52:28 +01:00
metalefty 7738d111d5 Merge commit from fork
CVE-2026-35512: Heap overflow in dynvc processing
2026-04-14 17:00:20 +09:00
metalefty 084eb2237e Merge commit from fork
CVE-2026-33689: Fix length check on channel open
2026-04-14 16:43:27 +09:00
metalefty 2e465c0b3a Merge commit from fork
CVE-2026-33145: Default AllowAlternateShell to 'no'
2026-04-14 15:14:20 +09:00
metalefty 16c971a437 Merge commit from fork
security: vulns in neutrinordp fragment reassembly
2026-04-14 15:07:03 +09:00
metalefty 6d1f89a919 Merge commit from fork
CVE-2026-33516 : Address potential OOB read
2026-04-14 15:01:23 +09:00
metalefty 1bacf22fb7 Merge commit from fork
Check HMAC values when non-TLS connections are used
2026-04-14 14:06:45 +09:00
metalefty 220a50b1d2 Merge commit from fork
CVE-2026-32624: buffer overflow if domain sep used
2026-04-14 09:30:27 +09:00
jsorg71 832edcab20 Merge pull request #3779 from jsorg71/instfiles_err
remove keymap file before creating sym link
2026-04-06 12:05:57 -07:00
Jay Sorg 05210adb22 use -f when creating sym link 2026-04-06 10:29:17 -07:00
matt335672 99dfacfffc Merge pull request #3755 from matt335672/gfx_resize
resizing: Simplify GFX resizing
2026-04-06 12:46:46 +01:00
matt335672 41a4af0a36 CVE-2026-35512: Heap overflow in dynvc processing
Length checking for the EGFX dynamic virtual channel is inadequate,
allowing for heap overflows to be forced by a malicious client before
authentication.
2026-04-06 12:39:32 +01:00
matt335672 6831249bed CVE-2026-33516 : Address potential OOB read
The codec list processing code contains a potential out-of-bounds
read, as the length check comes after the data is read.
2026-04-02 11:23:42 +01:00