6.6

CVE-2020-11524

Exploit

libfreerdp/codec/interleaved.c in FreeRDP versions > 1.0 through 2.0.0-rc4 has an Out-of-bounds Write.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
FreerdpFreerdp Version > 1.0.0 < 2.0.0
FreerdpFreerdp Version2.0.0 Update-
FreerdpFreerdp Version2.0.0 Updaterc0
FreerdpFreerdp Version2.0.0 Updaterc1
FreerdpFreerdp Version2.0.0 Updaterc2
FreerdpFreerdp Version2.0.0 Updaterc3
FreerdpFreerdp Version2.0.0 Updaterc4
CanonicalUbuntu Linux Version18.04 SwEditionlts
CanonicalUbuntu Linux Version19.10
CanonicalUbuntu Linux Version20.04 SwEditionlts
OpensuseLeap Version15.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.64% 0.697
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.6 0.7 5.9
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 6 6.8 6.4
AV:N/AC:M/Au:S/C:P/I:P/A:P
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.