CVE-2018-8794
published 2019-02-05CVE-2018-8794: rdesktop versions up to and including v1.8.3 contain an Integer Overflow that leads to an Out-Of-Bounds Write in function process_bitmap_updates() and results…
PriorityP351critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
6.66%
93.1th percentile
rdesktop versions up to and including v1.8.3 contain an Integer Overflow that leads to an Out-Of-Bounds Write in function process_bitmap_updates() and results in a memory corruption and possibly even a remote code execution.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| check_point_software_technologies_ltd | rdesktop | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | rdesktop | < rdesktop 1.8.4-1 (bookworm) | rdesktop 1.8.4-1 (bookworm) |
| opensuse | leap | — | — |
| rdesktop | rdesktop | <= 1.8.3 | — |
| rdesktop | rdesktop | >= 0 < 1.8.4-1 | 1.8.4-1 |
| rdesktop | rdesktop | >= 0 < 1.8.4-1 | 1.8.4-1 |
| rdesktop | rdesktop | >= 0 < 1.8.4-1 | 1.8.4-1 |
| rdesktop | rdesktop | >= 0 < 1.8.4-1 | 1.8.4-1 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
rdesktop: Memory corruption in process_bitmap_data
vendor_redhat·2019-01-04·CVSS 9.8
CVE-2018-8794 [CRITICAL] CWE-119 rdesktop: Memory corruption in process_bitmap_data
rdesktop: Memory corruption in process_bitmap_data
rdesktop versions up to and including v1.8.3 contain an Integer Overflow that leads to an Out-Of-Bounds Write in function process_bitmap_updates() and results in a memory corruption and possibly even a remote code execution.
Package: rdesktop (Red Hat Enterprise Linux 5) - Will not fix
Package: rdesktop (Red Hat Enterprise Linux 6) - Will not fix
Debian
CVE-2018-8794: rdesktop - rdesktop versions up to and including v1.8.3 contain an Integer Overflow that le...
vendor_debian·2018·CVSS 9.8
CVE-2018-8794 [CRITICAL] CVE-2018-8794: rdesktop - rdesktop versions up to and including v1.8.3 contain an Integer Overflow that le...
rdesktop versions up to and including v1.8.3 contain an Integer Overflow that leads to an Out-Of-Bounds Write in function process_bitmap_updates() and results in a memory corruption and possibly even a remote code execution.
Scope: local
bookworm: resolved (fixed in 1.8.4-1)
bullseye: resolved (fixed in 1.8.4-1)
forky: resolved (fixed in 1.8.4-1)
sid: resolved (fixed in 1.8.4-1)
trixie: resolved (fixed in 1.8.4-1)
GHSA
GHSA-8v6p-g8m9-hj76: rdesktop versions up to and including v1
ghsa_unreviewed·2022-05-13
CVE-2018-8794 [CRITICAL] CWE-787 GHSA-8v6p-g8m9-hj76: rdesktop versions up to and including v1
rdesktop versions up to and including v1.8.3 contain an Integer Overflow that leads to an Out-Of-Bounds Write in function process_bitmap_updates() and results in a memory corruption and possibly even a remote code execution.
OSV
CVE-2018-8794: rdesktop versions up to and including v1
osv·2019-02-05·CVSS 9.8
CVE-2018-8794 [CRITICAL] CVE-2018-8794: rdesktop versions up to and including v1
rdesktop versions up to and including v1.8.3 contain an Integer Overflow that leads to an Out-Of-Bounds Write in function process_bitmap_updates() and results in a memory corruption and possibly even a remote code execution.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-8794 opensmtpd: An out-of-bounds read could lead to remote code execution
bugzilla·2020-02-25·CVSS 9.8
CVE-2020-8794 [CRITICAL] CVE-2020-8794 opensmtpd: An out-of-bounds read could lead to remote code execution
CVE-2020-8794 opensmtpd: An out-of-bounds read could lead to remote code execution
An out-of-bounds read introduced in commit 80c6a60c, "when peer outputs a multi-line response ..." could lead to remote code execution either
as root, after May 2018 (commit a8e22235, "switch smtpd to new grammar"); or as any non-root user, before May 2018.
Upstream advisory:
https://www.openwall.com/lists/oss-security/2020/02/24/5
Discussion:
Created opensmtpd tracking bugs for this issue:
Affects: epel-all [bug 1809061]
Affects: fedora-all [bug 1809060]
---
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.
Bugzilla
CVE-2018-8794 rdesktop: Memory corruption in process_bitmap_data
bugzilla·2019-01-29·CVSS 9.8
CVE-2018-8794 [CRITICAL] CVE-2018-8794 rdesktop: Memory corruption in process_bitmap_data
CVE-2018-8794 rdesktop: Memory corruption in process_bitmap_data
A flaw was found in rdesktop before 1.8.4. A memory corruption issue in process_bitmap_data function may lead to denial of service.
Upstream patch:
https://github.com/rdesktop/rdesktop/commit/766ebcf6f23ccfe8323ac10242ae6e127d4505d2
https://github.com/rdesktop/rdesktop/releases/tag/v1.8.4
Discussion:
Created rdesktop tracking bugs for this issue:
Affects: fedora-all [bug 1670427]
---
Note:
You need to connect to a malicious or a MITM RDP server in order to trigger this flaw.
Bugzilla
CVE-2018-20174 CVE-2018-20175 CVE-2018-20176 CVE-2018-20177 CVE-2018-20178 CVE-2018-20179 CVE-2018-20180 CVE-2018-20181 CVE-2018-20182 CVE-2018-8791 CVE-2018-8792 CVE-2018-8793 CVE-2018-8794 CVE-2018-
bugzilla·2019-01-29·CVSS 7.5
CVE-2018-20174 [HIGH] CVE-2018-20174 CVE-2018-20175 CVE-2018-20176 CVE-2018-20177 CVE-2018-20178 CVE-2018-20179 CVE-2018-20180 CVE-2018-20181 CVE-2018-20182 CVE-2018-8791 CVE-2018-8792 CVE-2018-8793 CVE-2018-8794 CVE-2018-
CVE-2018-20174 CVE-2018-20175 CVE-2018-20176 CVE-2018-20177 CVE-2018-20178 CVE-2018-20179 CVE-2018-20180 CVE-2018-20181 CVE-2018-20182 CVE-2018-8791 CVE-2018-8792 CVE-2018-8793 CVE-2018-8794 CVE-2018-8795 ... rdesktop: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant to
http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00040.htmlhttp://www.securityfocus.com/bid/106938https://github.com/rdesktop/rdesktop/commit/4dca546d04321a610c1835010b5dad85163b65e1https://lists.debian.org/debian-lts-announce/2019/02/msg00030.htmlhttps://research.checkpoint.com/reverse-rdp-attack-code-execution-on-rdp-clients/https://security.gentoo.org/glsa/201903-06https://www.debian.org/security/2019/dsa-4394http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00040.htmlhttp://www.securityfocus.com/bid/106938https://github.com/rdesktop/rdesktop/commit/4dca546d04321a610c1835010b5dad85163b65e1https://lists.debian.org/debian-lts-announce/2019/02/msg00030.htmlhttps://research.checkpoint.com/reverse-rdp-attack-code-execution-on-rdp-clients/https://security.gentoo.org/glsa/201903-06https://www.debian.org/security/2019/dsa-4394
2019-02-05
Published