9.8

CVE-2018-8784

Exploit
FreeRDP prior to version 2.0.0-rc4 contains a Heap-Based Buffer Overflow in function zgfx_decompress_segment() that results in a memory corruption and probably even a remote code execution.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Freerdp ≫ Freerdp Version <= 1.2.0
Freerdp ≫ Freerdp Version 2.0.0 Update rc1
Freerdp ≫ Freerdp Version 2.0.0 Update rc2
Freerdp ≫ Freerdp Version 2.0.0 Update rc3
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 18.10
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 7.29% 0.936
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

http://www.securityfocus.com/bid/106938
Third Party Advisory
VDB Entry
https://github.com/FreeRDP/FreeRDP/commit/17c363a5162fd4dc77b1df54e48d7bd9bf6b3be7
Patch
Vendor Advisory
https://research.checkpoint.com/reverse-rdp-attack-code-execution-on-rdp-clients/
Third Party Advisory
Exploit
https://usn.ubuntu.com/3845-1/
Third Party Advisory