CVE-2020-13396
published 2020-05-22CVE-2020-13396: An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) read vulnerability has been detected in ntlm_read_ChallengeMessage in…
PriorityP335high7.1CVSS 3.1
AVNACLPRLUINSUCHINAL
EPSS
2.34%
81.8th percentile
An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) read vulnerability has been detected in ntlm_read_ChallengeMessage in winpr/libwinpr/sspi/NTLM/ntlm_message.c.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | freerdp2 | < freerdp2 2.1.1+dfsg1-1 (bookworm) | freerdp2 2.1.1+dfsg1-1 (bookworm) |
| freerdp | freerdp | < 2.1.1 | 2.1.1 |
| opensuse | leap | — | — |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:P
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
FreeRDP vulnerabilities
vendor_ubuntu·2020-11-26
CVE-2020-11045 FreeRDP vulnerabilities
Title: FreeRDP vulnerabilities
Summary: Several security issues were fixed in FreeRDP.
It was discovered that FreeRDP incorrectly handled certain memory
operations. A remote attacker could use this issue to cause FreeRDP to
crash, resulting in a denial of service, or possibly execute arbitrary
code.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
FreeRDP vulnerabilities
vendor_ubuntu·2020-06-04
CVE-2020-11042 FreeRDP vulnerabilities
Title: FreeRDP vulnerabilities
Summary: Several security issues were fixed in FreeRDP.
It was discovered that FreeRDP incorrectly handled certain memory
operations. A remote attacker could use this issue to cause FreeRDP to
crash, resulting in a denial of service, or possibly execute arbitrary
code.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
FreeRDP vulnerabilities
vendor_ubuntu·2020-06-01
CVE-2018-1000852 FreeRDP vulnerabilities
Title: FreeRDP vulnerabilities
Summary: Several security issues were fixed in FreeRDP.
It was discovered that FreeRDP incorrectly handled certain memory
operations. A remote attacker could use this issue to cause FreeRDP to
crash, resulting in a denial of service, or possibly exeucte arbitrary
code.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. In general, a standard system update will make all the necessary
changes.
Red Hat
freerdp: Out-of-bounds read in ntlm_read_ChallengeMessage in winpr/libwinpr/sspi/NTLM/ntlm_message.c.
vendor_redhat·2020-05-22·CVSS 7.1
CVE-2020-13396 [HIGH] CWE-125 freerdp: Out-of-bounds read in ntlm_read_ChallengeMessage in winpr/libwinpr/sspi/NTLM/ntlm_message.c.
freerdp: Out-of-bounds read in ntlm_read_ChallengeMessage in winpr/libwinpr/sspi/NTLM/ntlm_message.c.
An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) read vulnerability has been detected in ntlm_read_ChallengeMessage in winpr/libwinpr/sspi/NTLM/ntlm_message.c.
Package: freerdp (Red Hat Enterprise Linux 6) - Out of support scope
Debian
CVE-2020-13396: freerdp2 - An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) read vul...
vendor_debian·2020·CVSS 7.1
CVE-2020-13396 [HIGH] CVE-2020-13396: freerdp2 - An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) read vul...
An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) read vulnerability has been detected in ntlm_read_ChallengeMessage in winpr/libwinpr/sspi/NTLM/ntlm_message.c.
Scope: local
bookworm: resolved (fixed in 2.1.1+dfsg1-1)
bullseye: resolved (fixed in 2.1.1+dfsg1-1)
GHSA
GHSA-5cv3-wf6w-ffmx: An issue was discovered in FreeRDP before 2
ghsa_unreviewed·2022-05-24
CVE-2020-13396 [LOW] CWE-125 GHSA-5cv3-wf6w-ffmx: An issue was discovered in FreeRDP before 2
An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) read vulnerability has been detected in ntlm_read_ChallengeMessage in winpr/libwinpr/sspi/NTLM/ntlm_message.c.
OSV
CVE-2020-13396: An issue was discovered in FreeRDP before 2
osv·2020-05-22·CVSS 7.1
CVE-2020-13396 [HIGH] CVE-2020-13396: An issue was discovered in FreeRDP before 2
An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) read vulnerability has been detected in ntlm_read_ChallengeMessage in winpr/libwinpr/sspi/NTLM/ntlm_message.c.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-13396 freerdp: Out-of-bounds read in ntlm_read_ChallengeMessage in winpr/libwinpr/sspi/NTLM/ntlm_message.c.
bugzilla·2020-05-28·CVSS 7.1
CVE-2020-13396 [HIGH] CVE-2020-13396 freerdp: Out-of-bounds read in ntlm_read_ChallengeMessage in winpr/libwinpr/sspi/NTLM/ntlm_message.c.
CVE-2020-13396 freerdp: Out-of-bounds read in ntlm_read_ChallengeMessage in winpr/libwinpr/sspi/NTLM/ntlm_message.c.
An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) read vulnerability has been detected in ntlm_read_ChallengeMessage in winpr/libwinpr/sspi/NTLM/ntlm_message.c.
Upstream Commits:
https://github.com/FreeRDP/FreeRDP/commit/48361c411e50826cb602c7aab773a8a20e1da6bc
https://github.com/FreeRDP/FreeRDP/commit/8fb6336a4072abcee8ce5bd6ae91104628c7bb69
Discussion:
Created freerdp tracking bugs for this issue:
Affects: epel-all [bug 1841190]
Created freerdp1.2 tracking bugs for this issue:
Affects: fedora-all [bug 1841191]
---
The patch adds length checking by computing the StartOffset and PayloadOffset with Stream_GetPosition(s) instead of Stream_Point
Bugzilla
CVE-2020-13396 freerdp1.2: freerdp: Out-of-bounds read in ntlm_read_ChallengeMessage in winpr/libwinpr/sspi/NTLM/ntlm_message.c. [fedora-all]
bugzilla·2020-05-28·CVSS 7.1
CVE-2020-13396 [HIGH] CVE-2020-13396 freerdp1.2: freerdp: Out-of-bounds read in ntlm_read_ChallengeMessage in winpr/libwinpr/sspi/NTLM/ntlm_message.c. [fedora-all]
CVE-2020-13396 freerdp1.2: freerdp: Out-of-bounds read in ntlm_read_ChallengeMessage in winpr/libwinpr/sspi/NTLM/ntlm_message.c. [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commi
Bugzilla
CVE-2020-13396 freerdp: Out-of-bounds read in ntlm_read_ChallengeMessage in winpr/libwinpr/sspi/NTLM/ntlm_message.c. [epel-all]
bugzilla·2020-05-28·CVSS 7.1
CVE-2020-13396 [HIGH] CVE-2020-13396 freerdp: Out-of-bounds read in ntlm_read_ChallengeMessage in winpr/libwinpr/sspi/NTLM/ntlm_message.c. [epel-all]
CVE-2020-13396 freerdp: Out-of-bounds read in ntlm_read_ChallengeMessage in winpr/libwinpr/sspi/NTLM/ntlm_message.c. [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00080.htmlhttps://github.com/FreeRDP/FreeRDP/commit/48361c411e50826cb602c7aab773a8a20e1da6bchttps://github.com/FreeRDP/FreeRDP/commit/8fb6336a4072abcee8ce5bd6ae91104628c7bb69https://github.com/FreeRDP/FreeRDP/compare/2.1.0...2.1.1https://lists.debian.org/debian-lts-announce/2020/08/msg00054.htmlhttps://lists.debian.org/debian-lts-announce/2023/10/msg00008.htmlhttps://usn.ubuntu.com/4379-1/https://usn.ubuntu.com/4382-1/http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00080.htmlhttps://github.com/FreeRDP/FreeRDP/commit/48361c411e50826cb602c7aab773a8a20e1da6bchttps://github.com/FreeRDP/FreeRDP/commit/8fb6336a4072abcee8ce5bd6ae91104628c7bb69https://github.com/FreeRDP/FreeRDP/compare/2.1.0...2.1.1https://lists.debian.org/debian-lts-announce/2020/08/msg00054.htmlhttps://lists.debian.org/debian-lts-announce/2023/10/msg00008.htmlhttps://usn.ubuntu.com/4379-1/https://usn.ubuntu.com/4382-1/
2020-05-22
Published