CVE-2017-6967: Neutrinolabs Xrdp
High severity, CVSS 7.3. EPSS: 1.2% chance of exploitation in the next 30 days.
xrdp 0.9.1 calls the PAM function auth_start_session() in an incorrect location, leading to PAM session modules not being properly initialized, with a potential consequence of incorrect configurations or elevation of privileges, aka a pam_limits.so bypass.
Affected products
- Neutrinolabs Xrdp: version 0.9.1 only
Published 2017-03-17. Last modified 2026-06-17.