cbcvebase.
CVE-2020-11041
published 2020-05-29

CVE-2020-11041: In FreeRDP less than or equal to 2.0.0, an outside controlled array index is used unchecked for data used as configuration for sound backend (alsa, oss, pulse…

PriorityP410low2.7CVSS 3.1
AVNACLPRHUINSUCNINAL
EPSS
1.54%
72.1th percentile
In FreeRDP less than or equal to 2.0.0, an outside controlled array index is used unchecked for data used as configuration for sound backend (alsa, oss, pulse, ...). The most likely outcome is a crash of the client instance followed by no or distorted sound or a session disconnect. If a user cannot upgrade to the patched version, a workaround is to disable sound for the session. This has been patched in 2.1.0.

Affected

5 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianfreerdp2< freerdp2 2.1.1+dfsg1-1 (bookworm)freerdp2 2.1.1+dfsg1-1 (bookworm)
freerdpfreerdp< 2.1.02.1.0
freerdpfreerdp<= 2.0.0
opensuseleap

CVSS provenance

nvdv3.12.7LOWCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv2.7LOW
vendor_debian2.2LOW
vendor_redhat2.2LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.