CVE-2018-1000852Out-of-bounds Read in Freerdp

CWE-125Out-of-bounds Read10 documents7 sources
Severity
6.5MEDIUMNVD
EPSS
0.8%
top 25.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 20
Latest updateMay 13

Description

FreeRDP FreeRDP 2.0.0-rc3 released version before commit 205c612820dac644d665b5bb1cdf437dc5ca01e3 contains a Other/Unknown vulnerability in channels/drdynvc/client/drdynvc_main.c, drdynvc_process_capability_request that can result in The RDP server can read the client's memory.. This attack appear to be exploitable via RDPClient must connect the rdp server with echo option. This vulnerability appears to have been fixed in after commit 205c612820dac644d665b5bb1cdf437dc5ca01e3.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:LExploitability: 3.9 | Impact: 2.5

Affected Packages2 packages

NVDfreerdp/freerdp< 2.0.0+1
debiandebian/freerdp2< freerdp2 2.0.0~git20181120.1.e21b72c95+dfsg1-1 (bookworm)

Also affects: Fedora 28, Ubuntu Linux 18.04, 19.10, 20.04

Patches

🔴Vulnerability Details

2
GHSA
GHSA-vr2x-32cg-pm8g: FreeRDP FreeRDP 22022-05-13
OSV
CVE-2018-1000852: FreeRDP FreeRDP 22018-12-20

📋Vendor Advisories

3
Ubuntu
FreeRDP vulnerabilities2020-06-01
Red Hat
freerdp: out of bounds read in drdynvc_process_capability_request2018-09-19
Debian
CVE-2018-1000852: freerdp2 - FreeRDP FreeRDP 2.0.0-rc3 released version before commit 205c612820dac644d665b5b...2018

💬Community

4
Bugzilla
CVE-2018-1000852 freerdp: out of bounds read in drdynvc_process_capability_request2018-12-21
Bugzilla
CVE-2018-1000852 freerdp: out of bounds read in drdynvc_process_capability_request [epel-6]2018-12-21
Bugzilla
CVE-2018-1000852 freerdp1.2: freerdp: out of bounds read in drdynvc_process_capability_request [fedora-all]2018-12-21
Bugzilla
CVE-2018-1000852 freerdp: out of bounds read in drdynvc_process_capability_request [fedora-28]2018-12-21
CVE-2018-1000852 — Out-of-bounds Read in Freerdp | cvebase