cbcvebase.

Debian Freerdp2 vulnerabilities

148 known vulnerabilities affecting debian/freerdp2.

Total CVEs
148
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL13HIGH34MEDIUM68LOW32

Vulnerabilities

Page 8 of 8
CVE-2020-11526P4LOWCVSS 2.2fixed in freerdp2 2.1.1+dfsg1-1 (bookworm)2020
CVE-2020-11526 [LOW] CVE-2020-11526: freerdp2 - libfreerdp/core/update.c in FreeRDP versions > 1.1 through 2.0.0-rc4 has an Out-... libfreerdp/core/update.c in FreeRDP versions > 1.1 through 2.0.0-rc4 has an Out-of-bounds Read. Scope: local bookworm: resolved (fixed in 2.1.1+dfsg1-1) bullseye: resolved (fixed in 2.1.1+dfsg1-1)
debian
CVE-2020-11058P4LOWCVSS 2.2fixed in freerdp2 2.1.1+dfsg1-1 (bookworm)2020
CVE-2020-11058 [LOW] CVE-2020-11058: freerdp2 - In FreeRDP after 1.1 and before 2.0.0, a stream out-of-bounds seek in rdp_read_f... In FreeRDP after 1.1 and before 2.0.0, a stream out-of-bounds seek in rdp_read_font_capability_set could lead to a later out-of-bounds read. As a result, a manipulated client or server might force a disconnect due to an invalid data read. This has been fixed in 2.0.0. Scope: local bookworm: resolved (fixed in 2.1.1+dfsg1-1) bullseye: resolved (fixed in 2.1.1+dfsg1-1
debian
CVE-2020-11041P4LOWCVSS 2.2fixed in freerdp2 2.1.1+dfsg1-1 (bookworm)2020
CVE-2020-11041 [LOW] CVE-2020-11041: freerdp2 - In FreeRDP less than or equal to 2.0.0, an outside controlled array index is use... In FreeRDP less than or equal to 2.0.0, an outside controlled array index is used unchecked for data used as configuration for sound backend (alsa, oss, pulse, ...). The most likely outcome is a crash of the client instance followed by no or distorted sound or a session disconnect. If a user cannot upgrade to the patched version, a workaround is to disable sound for
debian
CVE-2020-11046P4MEDIUMCVSS 5.5fixed in freerdp2 2.1.1+dfsg1-1 (bookworm)2020
CVE-2020-11046 [MEDIUM] CVE-2020-11046: freerdp2 - In FreeRDP after 1.0 and before 2.0.0, there is a stream out-of-bounds seek in u... In FreeRDP after 1.0 and before 2.0.0, there is a stream out-of-bounds seek in update_read_synchronize that could lead to a later out-of-bounds read. Scope: local bookworm: resolved (fixed in 2.1.1+dfsg1-1) bullseye: resolved (fixed in 2.1.1+dfsg1-1)
debian
CVE-2020-11043P4LOWCVSS 2.2fixed in freerdp2 2.1.1+dfsg1-1 (bookworm)2020
CVE-2020-11043 [LOW] CVE-2020-11043: freerdp2 - In FreeRDP less than or equal to 2.0.0, there is an out-of-bounds read in rfx_pr... In FreeRDP less than or equal to 2.0.0, there is an out-of-bounds read in rfx_process_message_tileset. Invalid data fed to RFX decoder results in garbage on screen (as colors). This has been patched in 2.1.0. Scope: local bookworm: resolved (fixed in 2.1.1+dfsg1-1) bullseye: resolved (fixed in 2.1.1+dfsg1-1)
debian
CVE-2020-11048P4LOWCVSS 2.2fixed in freerdp2 2.1.1+dfsg1-1 (bookworm)2020
CVE-2020-11048 [LOW] CVE-2020-11048: freerdp2 - In FreeRDP after 1.0 and before 2.0.0, there is an out-of-bounds read. It only a... In FreeRDP after 1.0 and before 2.0.0, there is an out-of-bounds read. It only allows to abort a session. No data extraction is possible. This has been fixed in 2.0.0. Scope: local bookworm: resolved (fixed in 2.1.1+dfsg1-1) bullseye: resolved (fixed in 2.1.1+dfsg1-1)
debian
CVE-2020-11525P4LOWCVSS 2.2fixed in freerdp2 2.1.1+dfsg1-1 (bookworm)2020
CVE-2020-11525 [LOW] CVE-2020-11525: freerdp2 - libfreerdp/cache/bitmap.c in FreeRDP versions > 1.0 through 2.0.0-rc4 has an Out... libfreerdp/cache/bitmap.c in FreeRDP versions > 1.0 through 2.0.0-rc4 has an Out of bounds read. Scope: local bookworm: resolved (fixed in 2.1.1+dfsg1-1) bullseye: resolved (fixed in 2.1.1+dfsg1-1)
debian
CVE-2020-11040P4LOWCVSS 2.2fixed in freerdp2 2.1.1+dfsg1-1 (bookworm)2020
CVE-2020-11040 [LOW] CVE-2020-11040: freerdp2 - In FreeRDP less than or equal to 2.0.0, there is an out-of-bound data read from ... In FreeRDP less than or equal to 2.0.0, there is an out-of-bound data read from memory in clear_decompress_subcode_rlex, visualized on screen as color. This has been patched in 2.1.0. Scope: local bookworm: resolved (fixed in 2.1.1+dfsg1-1) bullseye: resolved (fixed in 2.1.1+dfsg1-1)
debian
Debian Freerdp2 vulnerabilities | cvebase