Debian Rdesktop vulnerabilities
24 known vulnerabilities affecting debian/rdesktop.
Total CVEs
24
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL13HIGH10LOW1
Vulnerabilities
Page 1 of 2
CVE-2008-1802P3CRITICALCVSS 9.3PoCfixed in rdesktop 1.5.0-4+cvs20071006 (bookworm)2008
CVE-2008-1802 [CRITICAL] CVE-2008-1802: rdesktop - Buffer overflow in the process_redirect_pdu (rdp.c) function in rdesktop 1.5.0 a...
Buffer overflow in the process_redirect_pdu (rdp.c) function in rdesktop 1.5.0 allows remote attackers to execute arbitrary code via a Remote Desktop Protocol (RDP) redirect request with modified length fields.
Scope: local
bookworm: resolved (fixed in 1.5.0-4+cvs20071006)
bullseye: resolved (fixed in 1.5.0-4+cvs20071006)
forky: resolved (fixed in 1.5.0-4+cvs2007
debian
CVE-2008-1801P3CRITICALCVSS 9.3PoCfixed in rdesktop 1.5.0-4+cvs20071006 (bookworm)2008
CVE-2008-1801 [CRITICAL] CVE-2008-1801: rdesktop - Integer underflow in the iso_recv_msg function (iso.c) in rdesktop 1.5.0 allows ...
Integer underflow in the iso_recv_msg function (iso.c) in rdesktop 1.5.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a Remote Desktop Protocol (RDP) request with a small length field.
Scope: local
bookworm: resolved (fixed in 1.5.0-4+cvs20071006)
bullseye: resolved (fixed in 1.5.0-4+cvs20071006)
forky: reso
debian
CVE-2018-20181P3CRITICALCVSS 9.8fixed in rdesktop 1.8.4-1 (bookworm)2018
CVE-2018-20181 [CRITICAL] CVE-2018-20181: rdesktop - rdesktop versions up to and including v1.8.3 contain an Integer Underflow that l...
rdesktop versions up to and including v1.8.3 contain an Integer Underflow that leads to a Heap-Based Buffer Overflow in the function seamless_process() and results in memory corruption and probably even a remote code execution.
Scope: local
bookworm: resolved (fixed in 1.8.4-1)
bullseye: resolved (fixed in 1.8.4-1)
forky: resolved (fixed in 1.8.4-1)
sid: resolv
debian
CVE-2018-20180P3CRITICALCVSS 9.8fixed in rdesktop 1.8.4-1 (bookworm)2018
CVE-2018-20180 [CRITICAL] CVE-2018-20180: rdesktop - rdesktop versions up to and including v1.8.3 contain an Integer Underflow that l...
rdesktop versions up to and including v1.8.3 contain an Integer Underflow that leads to a Heap-Based Buffer Overflow in the function rdpsnddbg_process() and results in memory corruption and probably even a remote code execution.
Scope: local
bookworm: resolved (fixed in 1.8.4-1)
bullseye: resolved (fixed in 1.8.4-1)
forky: resolved (fixed in 1.8.4-1)
sid: resol
debian
CVE-2018-20179P3CRITICALCVSS 9.8fixed in rdesktop 1.8.4-1 (bookworm)2018
CVE-2018-20179 [CRITICAL] CVE-2018-20179: rdesktop - rdesktop versions up to and including v1.8.3 contain an Integer Underflow that l...
rdesktop versions up to and including v1.8.3 contain an Integer Underflow that leads to a Heap-Based Buffer Overflow in the function lspci_process() and results in memory corruption and probably even a remote code execution.
Scope: local
bookworm: resolved (fixed in 1.8.4-1)
bullseye: resolved (fixed in 1.8.4-1)
forky: resolved (fixed in 1.8.4-1)
sid: resolved
debian
CVE-2018-20177P3CRITICALCVSS 9.8fixed in rdesktop 1.8.4-1 (bookworm)2018
CVE-2018-20177 [CRITICAL] CVE-2018-20177: rdesktop - rdesktop versions up to and including v1.8.3 contain an Integer Overflow that le...
rdesktop versions up to and including v1.8.3 contain an Integer Overflow that leads to a Heap-Based Buffer Overflow in the function rdp_in_unistr() and results in memory corruption and possibly even a remote code execution.
Scope: local
bookworm: resolved (fixed in 1.8.4-1)
bullseye: resolved (fixed in 1.8.4-1)
forky: resolved (fixed in 1.8.4-1)
sid: resolved (
debian
CVE-2018-8795P3CRITICALCVSS 9.8fixed in rdesktop 1.8.4-1 (bookworm)2018
CVE-2018-8795 [CRITICAL] CVE-2018-8795: rdesktop - rdesktop versions up to and including v1.8.3 contain an Integer Overflow that le...
rdesktop versions up to and including v1.8.3 contain an Integer Overflow that leads to a Heap-Based Buffer Overflow in function process_bitmap_updates() and results in a memory corruption and probably even a remote code execution.
Scope: local
bookworm: resolved (fixed in 1.8.4-1)
bullseye: resolved (fixed in 1.8.4-1)
forky: resolved (fixed in 1.8.4-1)
sid: resol
debian
CVE-2018-8793P3CRITICALCVSS 9.8fixed in rdesktop 1.8.4-1 (bookworm)2018
CVE-2018-8793 [CRITICAL] CVE-2018-8793: rdesktop - rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflo...
rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflow in function cssp_read_tsrequest() that results in a memory corruption and probably even a remote code execution.
Scope: local
bookworm: resolved (fixed in 1.8.4-1)
bullseye: resolved (fixed in 1.8.4-1)
forky: resolved (fixed in 1.8.4-1)
sid: resolved (fixed in 1.8.4-1)
trixie: resol
debian
CVE-2018-8800P3CRITICALCVSS 9.8fixed in rdesktop 1.8.4-1 (bookworm)2018
CVE-2018-8800 [CRITICAL] CVE-2018-8800: rdesktop - rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflo...
rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflow in function ui_clip_handle_data() that results in a memory corruption and probably even a remote code execution.
Scope: local
bookworm: resolved (fixed in 1.8.4-1)
bullseye: resolved (fixed in 1.8.4-1)
forky: resolved (fixed in 1.8.4-1)
sid: resolved (fixed in 1.8.4-1)
trixie: resol
debian
CVE-2018-20182P3CRITICALCVSS 9.8fixed in rdesktop 1.8.4-1 (bookworm)2018
CVE-2018-20182 [CRITICAL] CVE-2018-20182: rdesktop - rdesktop versions up to and including v1.8.3 contain a Buffer Overflow over the ...
rdesktop versions up to and including v1.8.3 contain a Buffer Overflow over the global variables in the function seamless_process_line() that results in memory corruption and probably even a remote code execution.
Scope: local
bookworm: resolved (fixed in 1.8.4-1)
bullseye: resolved (fixed in 1.8.4-1)
forky: resolved (fixed in 1.8.4-1)
sid: resolved (fixed in 1
debian
CVE-2018-8797P3CRITICALCVSS 9.8fixed in rdesktop 1.8.4-1 (bookworm)2018
CVE-2018-8797 [CRITICAL] CVE-2018-8797: rdesktop - rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflo...
rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflow in function process_plane() that results in a memory corruption and probably even a remote code execution.
Scope: local
bookworm: resolved (fixed in 1.8.4-1)
bullseye: resolved (fixed in 1.8.4-1)
forky: resolved (fixed in 1.8.4-1)
sid: resolved (fixed in 1.8.4-1)
trixie: resolved (f
debian
CVE-2018-8794P3CRITICALCVSS 9.8fixed in rdesktop 1.8.4-1 (bookworm)2018
CVE-2018-8794 [CRITICAL] CVE-2018-8794: rdesktop - rdesktop versions up to and including v1.8.3 contain an Integer Overflow that le...
rdesktop versions up to and including v1.8.3 contain an Integer Overflow that leads to an Out-Of-Bounds Write in function process_bitmap_updates() and results in a memory corruption and possibly even a remote code execution.
Scope: local
bookworm: resolved (fixed in 1.8.4-1)
bullseye: resolved (fixed in 1.8.4-1)
forky: resolved (fixed in 1.8.4-1)
sid: resolved (f
debian
CVE-2008-1803P3CRITICALCVSS 9.3fixed in rdesktop 1.5.0-4+cvs20071006 (bookworm)2008
CVE-2008-1803 [CRITICAL] CVE-2008-1803: rdesktop - Integer signedness error in the xrealloc function (rdesktop.c) in RDesktop 1.5.0...
Integer signedness error in the xrealloc function (rdesktop.c) in RDesktop 1.5.0 allows remote attackers to execute arbitrary code via unknown parameters that trigger a heap-based overflow. NOTE: the role of the channel_process function was not specified by the original researcher.
Scope: local
bookworm: resolved (fixed in 1.5.0-4+cvs20071006)
bullseye: resolved
debian
CVE-2018-8798P3HIGHCVSS 7.5fixed in rdesktop 1.8.4-1 (bookworm)2018
CVE-2018-8798 [HIGH] CVE-2018-8798: rdesktop - rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in fu...
rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function rdpsnd_process_ping() that results in an information leak.
Scope: local
bookworm: resolved (fixed in 1.8.4-1)
bullseye: resolved (fixed in 1.8.4-1)
forky: resolved (fixed in 1.8.4-1)
sid: resolved (fixed in 1.8.4-1)
trixie: resolved (fixed in 1.8.4-1)
debian
CVE-2018-8791P3HIGHCVSS 7.5fixed in rdesktop 1.8.4-1 (bookworm)2018
CVE-2018-8791 [HIGH] CVE-2018-8791: rdesktop - rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in fu...
rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function rdpdr_process() that results in an information leak.
Scope: local
bookworm: resolved (fixed in 1.8.4-1)
bullseye: resolved (fixed in 1.8.4-1)
forky: resolved (fixed in 1.8.4-1)
sid: resolved (fixed in 1.8.4-1)
trixie: resolved (fixed in 1.8.4-1)
debian
CVE-2018-20174P3HIGHCVSS 7.5fixed in rdesktop 1.8.4-1 (bookworm)2018
CVE-2018-20174 [HIGH] CVE-2018-20174: rdesktop - rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in th...
rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in the function ui_clip_handle_data() that results in an information leak.
Scope: local
bookworm: resolved (fixed in 1.8.4-1)
bullseye: resolved (fixed in 1.8.4-1)
forky: resolved (fixed in 1.8.4-1)
sid: resolved (fixed in 1.8.4-1)
trixie: resolved (fixed in 1.8.4-1)
debian
CVE-2018-20178P3HIGHCVSS 7.5fixed in rdesktop 1.8.4-1 (bookworm)2018
CVE-2018-20178 [HIGH] CVE-2018-20178: rdesktop - rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in th...
rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in the function process_demand_active() that results in a Denial of Service (segfault).
Scope: local
bookworm: resolved (fixed in 1.8.4-1)
bullseye: resolved (fixed in 1.8.4-1)
forky: resolved (fixed in 1.8.4-1)
sid: resolved (fixed in 1.8.4-1)
trixie: resolved (fixed in 1.8.4-1)
debian
CVE-2018-20175P3HIGHCVSS 7.5fixed in rdesktop 1.8.4-1 (bookworm)2018
CVE-2018-20175 [HIGH] CVE-2018-20175: rdesktop - rdesktop versions up to and including v1.8.3 contains several Integer Signedness...
rdesktop versions up to and including v1.8.3 contains several Integer Signedness errors that lead to Out-Of-Bounds Reads in the file mcs.c and result in a Denial of Service (segfault).
Scope: local
bookworm: resolved (fixed in 1.8.4-1)
bullseye: resolved (fixed in 1.8.4-1)
forky: resolved (fixed in 1.8.4-1)
sid: resolved (fixed in 1.8.4-1)
trixie: resolved (fixed i
debian
CVE-2018-8799P3HIGHCVSS 7.5fixed in rdesktop 1.8.4-1 (bookworm)2018
CVE-2018-8799 [HIGH] CVE-2018-8799: rdesktop - rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in fu...
rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function process_secondary_order() that results in a Denial of Service (segfault).
Scope: local
bookworm: resolved (fixed in 1.8.4-1)
bullseye: resolved (fixed in 1.8.4-1)
forky: resolved (fixed in 1.8.4-1)
sid: resolved (fixed in 1.8.4-1)
trixie: resolved (fixed in 1.8.4-1)
debian
CVE-2018-8796P3HIGHCVSS 7.5fixed in rdesktop 1.8.4-1 (bookworm)2018
CVE-2018-8796 [HIGH] CVE-2018-8796: rdesktop - rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in fu...
rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function process_bitmap_updates() that results in a Denial of Service (segfault).
Scope: local
bookworm: resolved (fixed in 1.8.4-1)
bullseye: resolved (fixed in 1.8.4-1)
forky: resolved (fixed in 1.8.4-1)
sid: resolved (fixed in 1.8.4-1)
trixie: resolved (fixed in 1.8.4-1)
debian
1 / 2Next →