5.9

CVE-2020-11042

Exploit

Out-of-bounds Read in FreeRDP

In FreeRDP greater than 1.1 and before 2.0.0, there is an out-of-bounds read in update_read_icon_info. It allows reading a attacker-defined amount of client memory (32bit unsigned -> 4GB) to an intermediate buffer. This can be used to crash the client or store information for later retrieval. This has been patched in 2.0.0.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Freerdp ≫ Freerdp Version > 1.1.0 < 2.0.0
Debian ≫ Debian Linux Version 9.0
Debian ≫ Debian Linux Version 10.0
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 19.10
Canonical ≫ Ubuntu Linux Version 20.04 SwEdition lts
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.77% 0.752
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.9 0.7 5.2
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:H
NIST 4.9 6.8 4.9
AV:N/AC:M/Au:S/C:P/I:N/A:P
security-advisories@github.com 5.5 1.3 3.7
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:L
CWE-125 Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

https://lists.debian.org/debian-lts-announce/2020/08/msg00054.html
Third Party Advisory
https://usn.ubuntu.com/4379-1/
Third Party Advisory
https://github.com/FreeRDP/FreeRDP/commit/6b2bc41935e53b0034fe5948aeeab4f32e80f30f
Patch
Third Party Advisory
https://github.com/FreeRDP/FreeRDP/issues/6010
Third Party Advisory
Exploit
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-9jp6-5vf2-cx2q
Third Party Advisory
https://lists.debian.org/debian-lts-announce/2023/10/msg00008.html
Mailing List
https://usn.ubuntu.com/4382-1/
Third Party Advisory