CVE-2013-1430: Debian Linux

Critical severity, CVSS 9.8. EPSS: 1.3% chance of exploitation in the next 30 days.

An issue was discovered in xrdp before 0.9.1. When successfully logging in using RDP into an xrdp session, the file ~/.vnc/sesman_${username}_passwd is created. Its content is the equivalent of the user's cleartext password, DES encrypted with a known key.

Affected products

  • Debian Debian Linux: version 7.0 only; version 8.0 only
  • Neutrinolabs Xrdp: up to and including 0.8.0

Published 2016-12-16. Last modified 2026-06-16.