CVE-2020-11048Out-of-bounds Read in Freerdp

CWE-125Out-of-bounds Read12 documents8 sources
Severity
2.2LOWNVD
EPSS
0.1%
top 68.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 7
Latest updateNov 26

Description

In FreeRDP after 1.0 and before 2.0.0, there is an out-of-bounds read. It only allows to abort a session. No data extraction is possible. This has been fixed in 2.0.0.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:LExploitability: 0.7 | Impact: 1.4

Affected Packages2 packages

NVDfreerdp/freerdp1.0.02.0.0
CVEListV5freerdp/freerdp> 1.0, < 2.0.0

Also affects: Debian Linux 10.0, 9.0, Ubuntu Linux 16.04, 18.04, 19.10, 20.04

Patches

🔴Vulnerability Details

2
CVEList
Out-of-bounds Read in FreeRDPrdp_read_flow_control_pdu2020-05-07
OSV
CVE-2020-11048: In FreeRDP after 12020-05-07

📋Vendor Advisories

6
Ubuntu
FreeRDP vulnerabilities2020-11-26
Oracle
Oracle Oracle Communications Risk Matrix: Core (PHP) — CVE-2019-110482020-10-15
Ubuntu
FreeRDP vulnerabilities2020-06-04
Ubuntu
FreeRDP vulnerabilities2020-06-01
Red Hat
freerdp: out-of-bounds read could result in aborting the session2020-04-09

💬Community

3
Bugzilla
CVE-2020-11048 freerdp1.2: freerdp: out-of-bounds read could result in aborting the session [fedora-all]2020-05-14
Bugzilla
CVE-2020-11048 freerdp: out-of-bounds read could result in aborting the session [epel-all]2020-05-14
Bugzilla
CVE-2020-11048 freerdp: out-of-bounds read could result in aborting the session2020-05-14
CVE-2020-11048 — Out-of-bounds Read in Freerdp | cvebase