In the xrdp package (in branches through 3.14) for Alpine Linux, RDP sessions are vulnerable to man-in-the-middle attacks because pre-generated RSA certificates and private keys are used.
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Aports | Alpinelinux | * | 3.14 (including) |
Xrdp | Ubuntu | trusty | * |
Xrdp | Ubuntu | xenial | * |