Description
In FreeRDP less than or equal to 2.0.0, there is an out-of-bound read in ntlm_read_NegotiateMessage. This has been fixed in 2.1.0.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:LExploitability: 2.8 | Impact: 2.5Attack Vector: Network
Complexity: Low
Privileges: Low
User Interaction: None
Scope: Unchanged
Confidentiality: Low
Integrity: None
Availability: Low
Affected Packages3 packages
Also affects: Debian Linux 10.0
🔴Vulnerability Details
2OSVCVE-2020-11088: In FreeRDP less than or equal to 2↗2020-05-29 ▶ CVEListOut-of-bound read in FreeRDP↗2020-05-29 ▶ 📋Vendor Advisories
2Red Hatfreerdp: out-of-bounds read in ntlm_read_NegotiateMessage↗2020-05-29 ▶ DebianCVE-2020-11088: freerdp2 - In FreeRDP less than or equal to 2.0.0, there is an out-of-bound read in ntlm_re...↗2020 ▶ 💬Community
5BugzillaCVE-2020-11088 freerdp: out-of-bounds read in ntlm_read_NegotiateMessage↗2020-06-04 ▶ BugzillaCVE-2020-11088 freerdp: out-of-bounds read in ntlm_read_NegotiateMessage [fedora-all]↗2020-06-04 ▶ BugzillaCVE-2020-11088 freerdp1.2: freerdp: out-of-bounds read in ntlm_read_NegotiateMessage [epel-7]↗2020-06-04 ▶ BugzillaCVE-2020-11088 freerdp1.2: freerdp: out-of-bounds read in ntlm_read_NegotiateMessage [fedora-all]↗2020-06-04 ▶ BugzillaCVE-2020-11088 freerdp: out-of-bounds read in ntlm_read_NegotiateMessage [epel-6]↗2020-06-04 ▶