CVE-2008-1803
published 2008-05-12CVE-2008-1803: Integer signedness error in the xrealloc function (rdesktop.c) in RDesktop 1.5.0 allows remote attackers to execute arbitrary code via unknown parameters that…
PriorityP344critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
6.74%
93.2th percentile
Integer signedness error in the xrealloc function (rdesktop.c) in RDesktop 1.5.0 allows remote attackers to execute arbitrary code via unknown parameters that trigger a heap-based overflow. NOTE: the role of the channel_process function was not specified by the original researcher.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | rdesktop | < rdesktop 1.5.0-4+cvs20071006 (bookworm) | rdesktop 1.5.0-4+cvs20071006 (bookworm) |
| rdesktop | rdesktop | — | — |
| rdesktop | rdesktop | >= 0 < 1.5.0-4+cvs20071006 | 1.5.0-4+cvs20071006 |
| rdesktop | rdesktop | >= 0 < 1.5.0-4+cvs20071006 | 1.5.0-4+cvs20071006 |
| rdesktop | rdesktop | >= 0 < 1.5.0-4+cvs20071006 | 1.5.0-4+cvs20071006 |
| rdesktop | rdesktop | >= 0 < 1.5.0-4+cvs20071006 | 1.5.0-4+cvs20071006 |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3CRITICAL
vendor_redhat9.3CRITICAL
vendor_ubuntu9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h6mv-mc2j-c734: Integer signedness error in the xrealloc function (rdesktop
ghsa_unreviewed·2022-05-01
CVE-2008-1803 [HIGH] GHSA-h6mv-mc2j-c734: Integer signedness error in the xrealloc function (rdesktop
Integer signedness error in the xrealloc function (rdesktop.c) in RDesktop 1.5.0 allows remote attackers to execute arbitrary code via unknown parameters that trigger a heap-based overflow. NOTE: the role of the channel_process function was not specified by the original researcher.
OSV
CVE-2008-1803: Integer signedness error in the xrealloc function (rdesktop
osv·2008-05-12·CVSS 9.3
CVE-2008-1803 [CRITICAL] CVE-2008-1803: Integer signedness error in the xrealloc function (rdesktop
Integer signedness error in the xrealloc function (rdesktop.c) in RDesktop 1.5.0 allows remote attackers to execute arbitrary code via unknown parameters that trigger a heap-based overflow. NOTE: the role of the channel_process function was not specified by the original researcher.
Ubuntu
rdesktop vulnerabilities
vendor_ubuntu·2008-09-18·CVSS 9.3
CVE-2008-1802 [CRITICAL] rdesktop vulnerabilities
Title: rdesktop vulnerabilities
Summary: rdesktop vulnerabilities
It was discovered that rdesktop did not properly validate the length
of packet headers when processing RDP requests. If a user were tricked
into connecting to a malicious server, an attacker could cause a
denial of service or possible execute arbitrary code with the
privileges of the user. (CVE-2008-1801)
Multiple buffer overflows were discovered in rdesktop when processing
RDP redirect requests. If a user were tricked into connecting to a
malicious server, an attacker could cause a denial of service or
possible execute arbitrary code with the privileges of the user.
(CVE-2008-1802)
It was discovered that rdesktop performed a signed integer comparison
when reallocating dynamic buffers which could result in a heap-based
o
Red Hat
rdesktop: channel_process() Integer Signedness Vulnerability
vendor_redhat·2008-05-07·CVSS 9.3
CVE-2008-1803 [CRITICAL] rdesktop: channel_process() Integer Signedness Vulnerability
rdesktop: channel_process() Integer Signedness Vulnerability
Integer signedness error in the xrealloc function (rdesktop.c) in RDesktop 1.5.0 allows remote attackers to execute arbitrary code via unknown parameters that trigger a heap-based overflow. NOTE: the role of the channel_process function was not specified by the original researcher.
Debian
CVE-2008-1803: rdesktop - Integer signedness error in the xrealloc function (rdesktop.c) in RDesktop 1.5.0...
vendor_debian·2008·CVSS 9.3
CVE-2008-1803 [CRITICAL] CVE-2008-1803: rdesktop - Integer signedness error in the xrealloc function (rdesktop.c) in RDesktop 1.5.0...
Integer signedness error in the xrealloc function (rdesktop.c) in RDesktop 1.5.0 allows remote attackers to execute arbitrary code via unknown parameters that trigger a heap-based overflow. NOTE: the role of the channel_process function was not specified by the original researcher.
Scope: local
bookworm: resolved (fixed in 1.5.0-4+cvs20071006)
bullseye: resolved (fixed in 1.5.0-4+cvs20071006)
forky: resolved (fixed in 1.5.0-4+cvs20071006)
sid: resolved (fixed in 1.5.0-4+cvs20071006)
trixie: resolved (fixed in 1.5.0-4+cvs20071006)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2008-1803 rdesktop: channel_process() Integer Signedness Vulnerability
bugzilla·2008-05-09·CVSS 9.3
CVE-2008-1803 [CRITICAL] CVE-2008-1803 rdesktop: channel_process() Integer Signedness Vulnerability
CVE-2008-1803 rdesktop: channel_process() Integer Signedness Vulnerability
iDefense published advisory affecting rdesktop:
DESCRIPTION:
Remote exploitation of an integer signedness vulnerability in rdesktop, as
included in various vendors' operating system distributions, allows attackers
to execute arbitrary code with the privileges of the logged-in user.
The vulnerability exists within the code responsible for reallocating dynamic
buffers. The rdesktop xrealloc() function uses a signed comparison to determine
if the requested allocation size is less than 1. When this occurs, the function
will incorrectly set the allocation size to be 1. This results in an improperly
sized heap buffer being allocated, which can later be overflowed.
ANALYSIS:
Exploitation of this vulnerability results i
Unit42
Threat Brief: Microsoft DNS Server Wormable Vulnerability CVE-2020-1350
blogs_unit42·2020-07-21·CVSS 10.0
CVE-2020-1350 [CRITICAL] Threat Brief: Microsoft DNS Server Wormable Vulnerability CVE-2020-1350
## Executive Summary
In July 2020, Microsoft released a security update, CVE-2020-1350 | Windows DNS Server Remote Code Execution Vulnerability, for a new remote code execution (RCE) vulnerability.
This vulnerability exists within the Microsoft Windows Domain Name System (DNS) Server due to the improper handling of certain types of requests, specifically over port 53/TCP. Exploitation of this vulnerability is possible by creating an integer overflow, potentially leading to remote code execution.
This vulnerability only affects Windows DNS and the following builds of the Microsoft Windows operating system (OS):
- Windows Server 2008/2008 R2
- Windows Server 2012/2012 R2
- Windows Server 2016
- Windows Server 2019
- Windows Server version 1803/1903/1909/2004 (Server Core installation)
#
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=698http://rdesktop.cvs.sourceforge.net/rdesktop/rdesktop/rdesktop.c?r1=1.161&r2=1.162&pathrev=HEADhttp://secunia.com/advisories/30118http://secunia.com/advisories/30248http://secunia.com/advisories/30713http://secunia.com/advisories/31224http://secunia.com/advisories/31928http://security.gentoo.org/glsa/glsa-200806-04.xmlhttp://sourceforge.net/mailarchive/message.php?msg_name=20080511065217.GA24455%40cse.unsw.EDU.AUhttp://sunsolve.sun.com/search/document.do?assetkey=1-26-240708-1http://support.avaya.com/elmodocs2/security/ASA-2008-360.htmhttp://www.debian.org/security/2008/dsa-1573http://www.mandriva.com/security/advisories?name=MDVSA-2008:101http://www.redhat.com/archives/fedora-package-announce/2008-May/msg00244.htmlhttp://www.redhat.com/archives/fedora-package-announce/2008-May/msg00270.htmlhttp://www.redhat.com/archives/fedora-package-announce/2008-May/msg00296.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0575.htmlhttp://www.securityfocus.com/bid/29097http://www.securitytracker.com/id?1019992http://www.ubuntu.com/usn/usn-646-1http://www.vupen.com/english/advisories/2008/1467/referenceshttp://www.vupen.com/english/advisories/2008/2403https://exchange.xforce.ibmcloud.com/vulnerabilities/42277https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9800http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=698http://rdesktop.cvs.sourceforge.net/rdesktop/rdesktop/rdesktop.c?r1=1.161&r2=1.162&pathrev=HEADhttp://secunia.com/advisories/30118http://secunia.com/advisories/30248http://secunia.com/advisories/30713http://secunia.com/advisories/31224http://secunia.com/advisories/31928http://security.gentoo.org/glsa/glsa-200806-04.xmlhttp://sourceforge.net/mailarchive/message.php?msg_name=20080511065217.GA24455%40cse.unsw.EDU.AUhttp://sunsolve.sun.com/search/document.do?assetkey=1-26-240708-1http://support.avaya.com/elmodocs2/security/ASA-2008-360.htmhttp://www.debian.org/security/2008/dsa-1573http://www.mandriva.com/security/advisories?name=MDVSA-2008:101http://www.redhat.com/archives/fedora-package-announce/2008-May/msg00244.htmlhttp://www.redhat.com/archives/fedora-package-announce/2008-May/msg00270.htmlhttp://www.redhat.com/archives/fedora-package-announce/2008-May/msg00296.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0575.htmlhttp://www.securityfocus.com/bid/29097http://www.securitytracker.com/id?1019992http://www.ubuntu.com/usn/usn-646-1http://www.vupen.com/english/advisories/2008/1467/referenceshttp://www.vupen.com/english/advisories/2008/2403https://exchange.xforce.ibmcloud.com/vulnerabilities/42277https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9800
2008-05-12
Published