Debian Package Tracker
Register | Log in
Subscribe

xrdp

Remote Desktop Protocol (RDP) server

Choose email to subscribe with

general
  • source: xrdp (main)
  • version: 0.10.1-4.1
  • maintainer: Debian Remote Maintainers (archive) (DMD)
  • uploaders: Thorsten Glaser [DMD] – Mike Gabriel [DMD] – Dominik George [DMD] – Alex Myczko [DMD]
  • arch: any
  • std-ver: 4.7.0
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 0.9.21.1-1~deb11u1
  • o-o-sec: 0.9.21.1-1~deb11u3
  • oldstable: 0.9.21.1-1+deb12u1
  • old-bpo: 0.9.24-5~bpo12+1
  • stable: 0.10.1-3.1
  • testing: 0.10.1-4
  • unstable: 0.10.1-4.1
  • exp: 0.10.5-1
versioned links
  • 0.9.21.1-1~deb11u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 0.9.21.1-1~deb11u3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 0.9.21.1-1+deb12u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 0.9.24-5~bpo12+1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 0.10.1-3.1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 0.10.1-4: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 0.10.1-4.1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 0.10.5-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • xrdp (1 bugs: 0, 0, 1, 0)
action needed
Marked for autoremoval on 13 March: #1126537 high
Version 0.10.1-4 of xrdp is marked for autoremoval from testing on Fri 13 Mar 2026. It is affected by #1126537. The removal of xrdp will also cause the removal of (transitive) reverse dependency: xorgxrdp. You should try to prevent the removal by fixing these RC bugs.
Created: 2026-02-04 Last update: 2026-02-04 23:32
Problems while searching for a new upstream version high
uscan had problems while searching for a new upstream version:
more than one main upstream tarballs listed.
Created: 2025-11-27 Last update: 2026-02-04 21:00
A new upstream version is available: 0.10.5 high
A new upstream version 0.10.5 is available, you should consider packaging it.
Created: 2025-11-27 Last update: 2026-02-04 21:00
1 security issue in trixie high

There is 1 open security issue in trixie.

1 important issue:
  • CVE-2025-68670: xrdp is an open source RDP server. xrdp before v0.10.5 contains an unauthenticated stack-based buffer overflow vulnerability. The issue stems from improper bounds checking when processing user domain information during the connection sequence. If exploited, the vulnerability could allow remote attackers to execute arbitrary code on the target system. The vulnerability allows an attacker to overwrite the stack buffer and the return address, which could theoretically be used to redirect the execution flow. The impact of this vulnerability is lessened if a compiler flag has been used to build the xrdp executable with stack canary protection. If this is the case, a second vulnerability would need to be used to leak the stack canary value. Upgrade to version 0.10.5 to receive a patch. Additionally, do not rely on stack canary protection on production systems.
Created: 2026-01-28 Last update: 2026-02-03 13:20
1 security issue in forky high

There is 1 open security issue in forky.

1 important issue:
  • CVE-2025-68670: xrdp is an open source RDP server. xrdp before v0.10.5 contains an unauthenticated stack-based buffer overflow vulnerability. The issue stems from improper bounds checking when processing user domain information during the connection sequence. If exploited, the vulnerability could allow remote attackers to execute arbitrary code on the target system. The vulnerability allows an attacker to overwrite the stack buffer and the return address, which could theoretically be used to redirect the execution flow. The impact of this vulnerability is lessened if a compiler flag has been used to build the xrdp executable with stack canary protection. If this is the case, a second vulnerability would need to be used to leak the stack canary value. Upgrade to version 0.10.5 to receive a patch. Additionally, do not rely on stack canary protection on production systems.
Created: 2026-01-28 Last update: 2026-02-03 13:20
1 security issue in bookworm high

There is 1 open security issue in bookworm.

1 important issue:
  • CVE-2025-68670: xrdp is an open source RDP server. xrdp before v0.10.5 contains an unauthenticated stack-based buffer overflow vulnerability. The issue stems from improper bounds checking when processing user domain information during the connection sequence. If exploited, the vulnerability could allow remote attackers to execute arbitrary code on the target system. The vulnerability allows an attacker to overwrite the stack buffer and the return address, which could theoretically be used to redirect the execution flow. The impact of this vulnerability is lessened if a compiler flag has been used to build the xrdp executable with stack canary protection. If this is the case, a second vulnerability would need to be used to leak the stack canary value. Upgrade to version 0.10.5 to receive a patch. Additionally, do not rely on stack canary protection on production systems.
Created: 2023-08-31 Last update: 2026-02-03 13:20
debian/patches: 1 patch with invalid metadata, 3 patches to forward upstream high

Among the 5 debian patches available in version 0.10.1-4.1 of the package, we noticed the following issues:

  • 1 patch with invalid metadata that ought to be fixed.
  • 3 patches where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2023-02-26 Last update: 2026-02-03 00:03
lintian reports 3 errors and 9 warnings high
Lintian reports 3 errors and 9 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2025-06-06 Last update: 2026-01-21 03:00
1 open merge request in Salsa normal
There is 1 open merge request for this package on Salsa. You should consider reviewing and/or merging these merge requests.
Created: 2025-08-19 Last update: 2025-12-21 15:00
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.3 instead of 4.7.0).
Created: 2025-02-21 Last update: 2026-02-02 17:30
testing migrations
  • excuses:
    • Migration status for xrdp (0.10.1-4 to 0.10.1-4.1): Waiting for test results or another package, or too young (no action required now - check later)
    • Issues preventing migration:
    • ∙ ∙ Too young, only 3 of 5 days old
    • Additional info (not blocking):
    • ∙ ∙ Updating xrdp will fix bugs in testing: #1126537
    • ∙ ∙ Piuparts tested OK - https://piuparts.debian.org/sid/source/x/xrdp.html
    • ∙ ∙ Reproducible on amd64
    • ∙ ∙ Reproducible on arm64
    • ∙ ∙ Reproducible on armhf
    • ∙ ∙ Reproducible on i386
    • ∙ ∙ Reproducible on ppc64el
    • Not considered
news
[rss feed]
  • [2026-02-02] Accepted xrdp 0.10.1-4.1 (source) into unstable (Salvatore Bonaccorso)
  • [2026-02-01] Accepted xrdp 0.9.21.1-1~deb11u3 (source) into oldoldstable-security (Utkarsh Gupta)
  • [2026-02-01] Accepted xrdp 0.10.5-1 (source) into experimental (Alex Myczko)
  • [2025-12-30] xrdp 0.10.1-4 MIGRATED to testing (Debian testing watch)
  • [2025-12-27] Accepted xrdp 0.10.1-4 (source) into unstable (Alex Myczko)
  • [2025-09-12] Accepted xrdp 0.10.4.1-2 (source) into experimental (Alex Myczko)
  • [2025-09-12] Accepted xrdp 0.10.4.1-1 (source) into experimental (Alex Myczko)
  • [2025-06-11] xrdp 0.10.1-3.1 MIGRATED to testing (Debian testing watch)
  • [2025-06-06] Accepted xrdp 0.10.1-3.1 (source) into unstable (Bastian Germann) (signed by: bage@debian.org)
  • [2025-05-31] Accepted xrdp 0.9.21.1-1+deb12u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Abhijith PA)
  • [2025-05-16] Accepted xrdp 0.9.21.1-1~deb11u2 (source amd64) into oldstable-security (Abhijith PA)
  • [2025-01-22] Accepted xrdp 0.10.2-2 (source) into experimental (Alex Myczko) (signed by: Gürkan Myczko)
  • [2025-01-21] Accepted xrdp 0.10.2-1 (source) into experimental (Alex Myczko) (signed by: Gürkan Myczko)
  • [2024-10-12] xrdp 0.10.1-3 MIGRATED to testing (Debian testing watch)
  • [2024-10-08] xrdp REMOVED from testing (Debian testing watch)
  • [2024-08-30] Accepted xrdp 0.10.1-3 (source) into unstable (Alex Myczko) (signed by: Gürkan Myczko)
  • [2024-08-21] Accepted xrdp 0.10.1-2 (source) into unstable (Alex Myczko) (signed by: Gürkan Myczko)
  • [2024-08-11] Accepted xrdp 0.10.1-1 (source) into unstable (Alex Myczko) (signed by: Gürkan Myczko)
  • [2024-07-22] Accepted xrdp 0.10.0-2 (source) into unstable (Alex Myczko) (signed by: Gürkan Myczko)
  • [2024-06-25] Accepted xrdp 0.9.24-5~bpo12+1 (source amd64) into stable-backports (Debian FTP Masters) (signed by: Gürkan Myczko)
  • [2024-05-21] xrdp 0.9.24-5 MIGRATED to testing (Debian testing watch)
  • [2024-05-16] Accepted xrdp 0.9.24-5 (source) into unstable (Alex Myczko) (signed by: Gürkan Myczko)
  • [2024-05-13] Accepted xrdp 0.10.0-1 (source) into experimental (Alex Myczko) (signed by: Gürkan Myczko)
  • [2024-04-25] xrdp 0.9.24-4 MIGRATED to testing (Debian testing watch)
  • [2024-04-16] Accepted xrdp 0.9.24-4 (source) into unstable (Alex Myczko) (signed by: Gürkan Myczko)
  • [2024-03-28] Accepted xrdp 0.10.0~beta2-1 (source) into experimental (Gürkan Myczko) (signed by: Gürkan Myczko)
  • [2024-03-11] Accepted xrdp 0.10.0~beta1-2 (source) into experimental (Gürkan Myczko) (signed by: Gürkan Myczko)
  • [2024-03-11] Accepted xrdp 0.10.0~beta1-1 (source) into experimental (Gürkan Myczko) (signed by: Gürkan Myczko)
  • [2024-02-17] xrdp 0.9.24-3 MIGRATED to testing (Debian testing watch)
  • [2024-02-11] Accepted xrdp 0.9.24-3 (source) into unstable (Gürkan Myczko) (signed by: Gürkan Myczko)
  • 1
  • 2
bugs [bug history graph]
  • all: 1
  • RC: 0
  • I&N: 0
  • M&W: 1
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian (3, 9)
  • buildd: logs, exp, reproducibility, cross
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • screenshots
  • debian patches
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 0.10.1-4.1
  • 13 bugs

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing