CVE-2020-11085
published 2020-05-29CVE-2020-11085: In FreeRDP before 2.1.0, there is an out-of-bounds read in cliprdr_read_format_list. Clipboard format data read (by client or server) might read data…
PriorityP414low3.5CVSS 3.1
AVNACLPRLUIRSUCNINAL
EPSS
1.71%
74.7th percentile
In FreeRDP before 2.1.0, there is an out-of-bounds read in cliprdr_read_format_list. Clipboard format data read (by client or server) might read data out-of-bounds. This has been fixed in 2.1.0.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | freerdp2 | < freerdp2 2.1.1+dfsg1-1 (bookworm) | freerdp2 2.1.1+dfsg1-1 (bookworm) |
| freerdp | freerdp | < 2.1.0 | 2.1.0 |
| opensuse | leap | — | — |
CVSS provenance
nvdv3.13.5LOWCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv3.5LOW
vendor_debian2.6LOW
vendor_redhat2.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2020-11085: In FreeRDP before 2
osv·2020-05-29·CVSS 3.5
CVE-2020-11085 [LOW] CVE-2020-11085: In FreeRDP before 2
In FreeRDP before 2.1.0, there is an out-of-bounds read in cliprdr_read_format_list. Clipboard format data read (by client or server) might read data out-of-bounds. This has been fixed in 2.1.0.
Red Hat
freerdp: out-of-bounds read in cliprdr_read_format_list function
vendor_redhat·2020-05-29·CVSS 2.6
CVE-2020-11085 [LOW] CWE-805 freerdp: out-of-bounds read in cliprdr_read_format_list function
freerdp: out-of-bounds read in cliprdr_read_format_list function
In FreeRDP before 2.1.0, there is an out-of-bounds read in cliprdr_read_format_list. Clipboard format data read (by client or server) might read data out-of-bounds. This has been fixed in 2.1.0.
Mitigation: To mitigate this flaw in vulnerable versions, clipboard support should be disabled for freerdp sessions.
Package: freerdp (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2020-11085: freerdp2 - In FreeRDP before 2.1.0, there is an out-of-bounds read in cliprdr_read_format_l...
vendor_debian·2020·CVSS 2.6
CVE-2020-11085 [LOW] CVE-2020-11085: freerdp2 - In FreeRDP before 2.1.0, there is an out-of-bounds read in cliprdr_read_format_l...
In FreeRDP before 2.1.0, there is an out-of-bounds read in cliprdr_read_format_list. Clipboard format data read (by client or server) might read data out-of-bounds. This has been fixed in 2.1.0.
Scope: local
bookworm: resolved (fixed in 2.1.1+dfsg1-1)
bullseye: resolved (fixed in 2.1.1+dfsg1-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-11085 freerdp: out-of-bounds read in cliprdr_read_format_list function [epel-6]
bugzilla·2020-06-04·CVSS 2.6
CVE-2020-11085 [LOW] CVE-2020-11085 freerdp: out-of-bounds read in cliprdr_read_format_list function [epel-6]
CVE-2020-11085 freerdp: out-of-bounds read in cliprdr_read_format_list function [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-6.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following template to fo
Bugzilla
CVE-2020-11085 freerdp1.2: freerdp: out-of-bounds read in cliprdr_read_format_list function [epel-7]
bugzilla·2020-06-04·CVSS 2.6
CVE-2020-11085 [LOW] CVE-2020-11085 freerdp1.2: freerdp: out-of-bounds read in cliprdr_read_format_list function [epel-7]
CVE-2020-11085 freerdp1.2: freerdp: out-of-bounds read in cliprdr_read_format_list function [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following te
Bugzilla
CVE-2020-11085 freerdp: out-of-bounds read in cliprdr_read_format_list function [fedora-all]
bugzilla·2020-06-04·CVSS 2.6
CVE-2020-11085 [LOW] CVE-2020-11085 freerdp: out-of-bounds read in cliprdr_read_format_list function [fedora-all]
CVE-2020-11085 freerdp: out-of-bounds read in cliprdr_read_format_list function [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple sup
Bugzilla
CVE-2020-11085 freerdp: out-of-bounds read in cliprdr_read_format_list function
bugzilla·2020-06-04·CVSS 2.6
CVE-2020-11085 [LOW] CVE-2020-11085 freerdp: out-of-bounds read in cliprdr_read_format_list function
CVE-2020-11085 freerdp: out-of-bounds read in cliprdr_read_format_list function
In FreeRDP before 2.1.0, there is an out-of-bounds read in cliprdr_read_format_list. Clipboard format data read (by client or server) might read data out-of-bounds. This has been fixed in 2.1.0.
Reference:
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-2j4w-v45m-95hf
Upstream commit:
https://github.com/FreeRDP/FreeRDP/commit/b73143cf7ee5fe4cdabcbf56908aa15d8a883821
Discussion:
Created freerdp tracking bugs for this issue:
Affects: epel-6 [bug 1844164]
Affects: fedora-all [bug 1844163]
Created freerdp1.2 tracking bugs for this issue:
Affects: epel-7 [bug 1844165]
Affects: fedora-all [bug 1844162]
---
Note that the flaw in the files reported for this CVE does not exist in any Red Hat Enter
Bugzilla
CVE-2020-11085 freerdp1.2: freerdp: out-of-bounds read in cliprdr_read_format_list function [fedora-all]
bugzilla·2020-06-04·CVSS 2.6
CVE-2020-11085 [LOW] CVE-2020-11085 freerdp1.2: freerdp: out-of-bounds read in cliprdr_read_format_list function [fedora-all]
CVE-2020-11085 freerdp1.2: freerdp: out-of-bounds read in cliprdr_read_format_list function [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00080.htmlhttps://github.com/FreeRDP/FreeRDP/commit/b73143cf7ee5fe4cdabcbf56908aa15d8a883821https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-2j4w-v45m-95hfhttps://lists.debian.org/debian-lts-announce/2023/10/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-07/msg00080.htmlhttps://github.com/FreeRDP/FreeRDP/commit/b73143cf7ee5fe4cdabcbf56908aa15d8a883821https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-2j4w-v45m-95hfhttps://lists.debian.org/debian-lts-announce/2023/10/msg00008.html
2020-05-29
Published