CVE-2018-8800
published 2019-02-05CVE-2018-8800: rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflow in function ui_clip_handle_data() that results in a memory corruption and…
PriorityP355critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
7.06%
93.5th percentile
rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflow in function ui_clip_handle_data() that results in a memory corruption and probably even a remote code execution.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| check_point_software_technologies_ltd | rdesktop | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | rdesktop | < rdesktop 1.8.4-1 (bookworm) | rdesktop 1.8.4-1 (bookworm) |
| opensuse | leap | — | — |
| rdesktop | rdesktop | <= 1.8.3 | — |
| rdesktop | rdesktop | >= 0 < 1.8.4-1 | 1.8.4-1 |
| rdesktop | rdesktop | >= 0 < 1.8.4-1 | 1.8.4-1 |
| rdesktop | rdesktop | >= 0 < 1.8.4-1 | 1.8.4-1 |
| rdesktop | rdesktop | >= 0 < 1.8.4-1 | 1.8.4-1 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_cisco8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-93cm-qxxv-xcv9: rdesktop versions up to and including v1
ghsa_unreviewed·2022-05-13
CVE-2018-8800 [CRITICAL] CWE-787 GHSA-93cm-qxxv-xcv9: rdesktop versions up to and including v1
rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflow in function ui_clip_handle_data() that results in a memory corruption and probably even a remote code execution.
OSV
CVE-2018-8800: rdesktop versions up to and including v1
osv·2019-02-05·CVSS 9.8
CVE-2018-8800 [CRITICAL] CVE-2018-8800: rdesktop versions up to and including v1
rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflow in function ui_clip_handle_data() that results in a memory corruption and probably even a remote code execution.
Cisco
Cisco IP Phone 8800 Series Arbitrary Script Injection Vulnerability
vendor_cisco·2019-01-09·CVSS 6.5
CVE-2018-0461 [MEDIUM] CWE-94 Cisco IP Phone 8800 Series Arbitrary Script Injection Vulnerability
Cisco IP Phone 8800 Series Arbitrary Script Injection Vulnerability
A vulnerability in the Cisco IP Phone 8800 Series Software could allow an unauthenticated, remote attacker to conduct an arbitrary script injection attack on an affected device.
The vulnerability exists because the software running on an affected device insufficiently validates user-supplied data. An attacker could exploit this vulnerability by persuading a user to click a malicious link provided to the user or through the interface of an affected device. A successful exploit could allow an attacker to execute arbitrary script code in the context of the user interface or access sensitive system-based information, which under normal circumstances should be prohibited.
There are no workarounds that address this vulnerabilit
Red Hat
rdesktop: Remote code execution in ui_clip_handle_data
vendor_redhat·2019-01-04·CVSS 9.8
CVE-2018-8800 [CRITICAL] CWE-119 rdesktop: Remote code execution in ui_clip_handle_data
rdesktop: Remote code execution in ui_clip_handle_data
rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflow in function ui_clip_handle_data() that results in a memory corruption and probably even a remote code execution.
Package: rdesktop (Red Hat Enterprise Linux 5) - Will not fix
Package: rdesktop (Red Hat Enterprise Linux 6) - Will not fix
Cisco
Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware Web UI Command Injection Vulnerability
vendor_cisco·2018-07-11·CVSS 8.8
CVE-2018-0341 [HIGH] CWE-77 Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware Web UI Command Injection Vulnerability
Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware Web UI Command Injection Vulnerability
A vulnerability in the web-based UI of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware could allow an authenticated, remote attacker to perform a command injection and execute commands with the privileges of the web server.
The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by including arbitrary shell commands in a specific user input field.
Cisco will release software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-2018
Cisco
Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware Session Initiation Protocol Denial of Service Vulnerability
vendor_cisco·2018-06-06·CVSS 7.5
CVE-2018-0316 [HIGH] CWE-399 Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware Session Initiation Protocol Denial of Service Vulnerability
Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware Session Initiation Protocol Denial of Service Vulnerability
A vulnerability in the Session Initiation Protocol (SIP) call-handling functionality of Cisco IP Phone 6800, 7800, and 8800 Series Phones with Multiplatform Firmware could allow an unauthenticated, remote attacker to cause an affected phone to reload unexpectedly, resulting in a temporary denial of service (DoS) condition.
The vulnerability exists because the firmware of an affected phone incorrectly handles errors that could occur when an incoming phone call is not answered. An attacker could exploit this vulnerability by sending a set of maliciously crafted SIP packets to an affected phone. A successful exploit could allow the attacker to cause the affected
Cisco
Cisco IP Phone 7800 Series and 8800 Series and Cisco Wireless IP Phone 8821 Denial of Service Vulnerability
vendor_cisco·2018-05-16·CVSS 5.8
CVE-2018-0325 [MEDIUM] CWE-20 Cisco IP Phone 7800 Series and 8800 Series and Cisco Wireless IP Phone 8821 Denial of Service Vulnerability
Cisco IP Phone 7800 Series and 8800 Series and Cisco Wireless IP Phone 8821 Denial of Service Vulnerability
A vulnerability in the Session Initiation Protocol (SIP) call-handling functionality of Cisco IP Phone 7800 Series, IP Phone 8800 Series, and Wireless IP Phone 8821 could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected phone.
The vulnerability is due to incomplete input validation of SIP Session Description Protocol (SDP) parameters by the SDP parser of an affected phone. An attacker could exploit this vulnerability by sending a malformed SIP packet to an affected phone. A successful exploit could allow the attacker to cause all active phone calls on the affected phone to be dropped while the SIP process on the phone unexpectedly
Debian
CVE-2018-8800: rdesktop - rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflo...
vendor_debian·2018·CVSS 9.8
CVE-2018-8800 [CRITICAL] CVE-2018-8800: rdesktop - rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflo...
rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflow in function ui_clip_handle_data() that results in a memory corruption and probably even a remote code execution.
Scope: local
bookworm: resolved (fixed in 1.8.4-1)
bullseye: resolved (fixed in 1.8.4-1)
forky: resolved (fixed in 1.8.4-1)
sid: resolved (fixed in 1.8.4-1)
trixie: resolved (fixed in 1.8.4-1)
Cisco
Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware Web UI Command Injection Vulnerability
vendor_cisco·CVSS 3.0
CVE-2018-0341 Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware Web UI Command Injection Vulnerability
CVE-2018-0341: Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware Web UI Command Injection Vulnerability
A vulnerability in the web-based UI of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware could allow an authenticated, remote attacker to perform a command injection and execute commands with the privileges of the web server. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by including arbitrary shell commands in a specific user input field. Cisco will release software updates that address this vulnerability. There are no
CVSS: 3.0
CWE: CWE-77, CWE-77
Bug IDs: CSCvi51426
Cisco
Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware Session Initiation Protocol Denial of Service Vulnerability
vendor_cisco·CVSS 3.0
CVE-2018-0316 Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware Session Initiation Protocol Denial of Service Vulnerability
CVE-2018-0316: Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware Session Initiation Protocol Denial of Service Vulnerability
A vulnerability in the Session Initiation Protocol (SIP) call-handling functionality of Cisco IP Phone 6800, 7800, and 8800 Series Phones with Multiplatform Firmware could allow an unauthenticated, remote attacker to cause an affected phone to reload unexpectedly, resulting in a temporary denial of service (DoS) condition. The vulnerability exists because the firmware of an affected phone incorrectly handles errors that could occur when an incoming phone call is not answered. An attacker could exploit this vulnerability by sending a set of maliciously crafted SIP packets to an affected phone. A successful exploit could allow the attacker to cause
Cisco
Cisco IP Phone 8800 Series Arbitrary Script Injection Vulnerability
vendor_cisco·CVSS 3.0
CVE-2018-0461 Cisco IP Phone 8800 Series Arbitrary Script Injection Vulnerability
CVE-2018-0461: Cisco IP Phone 8800 Series Arbitrary Script Injection Vulnerability
A vulnerability in the Cisco IP Phone 8800 Series Software could allow an unauthenticated, remote attacker to conduct an arbitrary script injection attack on an affected device. The vulnerability exists because the software running on an affected device insufficiently validates user-supplied data. An attacker could exploit this vulnerability by persuading a user to click a malicious link provided to the user or through the interface of an affected device. A successful exploit could allow an attacker to execute arbitrary script code in the context of the user interface or access sensitive system-based information, which under normal circumstances should be prohibited. There are no
CVSS: 3.0
CWE: CWE-94, CWE-9
Cisco
Cisco IP Phone 7800 Series and 8800 Series and Cisco Wireless IP Phone 8821 Denial of Service Vulnerability
vendor_cisco·CVSS 3.0
CVE-2018-0325 Cisco IP Phone 7800 Series and 8800 Series and Cisco Wireless IP Phone 8821 Denial of Service Vulnerability
CVE-2018-0325: Cisco IP Phone 7800 Series and 8800 Series and Cisco Wireless IP Phone 8821 Denial of Service Vulnerability
A vulnerability in the Session Initiation Protocol (SIP) call-handling functionality of Cisco IP Phone 7800 Series, IP Phone 8800 Series, and Wireless IP Phone 8821 could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected phone. The vulnerability is due to incomplete input validation of SIP Session Description Protocol (SDP) parameters by the SDP parser of an affected phone. An attacker could exploit this vulnerability by sending a malformed SIP packet to an affected phone. A successful exploit could allow the attacker to cause all active phone calls on the affected phone to be dropped while the SIP process on the phon
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00040.htmlhttp://www.securityfocus.com/bid/106938https://github.com/rdesktop/rdesktop/commit/4dca546d04321a610c1835010b5dad85163b65e1https://lists.debian.org/debian-lts-announce/2019/02/msg00030.htmlhttps://research.checkpoint.com/reverse-rdp-attack-code-execution-on-rdp-clients/https://security.gentoo.org/glsa/201903-06https://www.debian.org/security/2019/dsa-4394http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00040.htmlhttp://www.securityfocus.com/bid/106938https://github.com/rdesktop/rdesktop/commit/4dca546d04321a610c1835010b5dad85163b65e1https://lists.debian.org/debian-lts-announce/2019/02/msg00030.htmlhttps://research.checkpoint.com/reverse-rdp-attack-code-execution-on-rdp-clients/https://security.gentoo.org/glsa/201903-06https://www.debian.org/security/2019/dsa-4394
2019-02-05
Published