Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2008-1801Integer Overflow or Wraparound in Rdesktop

Severity
9.3CRITICALNVD
EPSS
36.7%
top 2.84%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedMay 12
Latest updateMay 1

Description

Integer underflow in the iso_recv_msg function (iso.c) in rdesktop 1.5.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a Remote Desktop Protocol (RDP) request with a small length field.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages3 packages

debiandebian/rdesktop< rdesktop 1.5.0-4+cvs20071006 (bookworm)
Debianrdesktop/rdesktop< 1.5.0-4+cvs20071006+3

🔴Vulnerability Details

2
GHSA
GHSA-fmmp-hrq3-7r3f: Integer underflow in the iso_recv_msg function (iso2022-05-01
OSV
CVE-2008-1801: Integer underflow in the iso_recv_msg function (iso2008-05-12

💥Exploits & PoCs

1
Exploit-DB
rdesktop 1.5.0 - 'iso_recv_msg()' Integer Underflow (PoC)2008-05-08

📋Vendor Advisories

3
Ubuntu
rdesktop vulnerabilities2008-09-18
Red Hat
rdesktop: iso_recv_msg() Integer Underflow Vulnerability2008-05-07
Debian
CVE-2008-1801: rdesktop - Integer underflow in the iso_recv_msg function (iso.c) in rdesktop 1.5.0 allows ...2008

💬Community

1
Bugzilla
CVE-2008-1801 rdesktop: iso_recv_msg() Integer Underflow Vulnerability2008-05-09