CVE-2020-11047 — Out-of-bounds Read in Freerdp
Severity
5.9MEDIUMNVD
CNA5.5
EPSS
0.1%
top 72.47%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 7
Latest updateJun 1
Description
In FreeRDP after 1.1 and before 2.0.0, there is an out-of-bounds read in autodetect_recv_bandwidth_measure_results. A malicious server can extract up to 8 bytes of client memory with a manipulated message by providing a short input and reading the measurement result data. This has been patched in 2.0.0.
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:HExploitability: 0.7 | Impact: 5.2
Affected Packages2 packages
Also affects: Debian Linux 10.0, Ubuntu Linux 18.04, 19.10, 20.04
Patches
🔴Vulnerability Details
2📋Vendor Advisories
3💬Community
3Bugzilla▶
CVE-2020-11047 freerdp: out-of-bounds read in autodetect_recv_bandwidth_measure_results function [epel-all]↗2020-05-14
Bugzilla▶
CVE-2020-11047 freerdp: out-of-bounds read in autodetect_recv_bandwidth_measure_results function↗2020-05-14
Bugzilla▶
CVE-2020-11047 freerdp1.2: freerdp: out-of-bounds read in autodetect_recv_bandwidth_measure_results function [fedora-all]↗2020-05-14