Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-17178

Опубликовано: 04 окт. 2019
Источник: debian
EPSS Низкий

Описание

HuffmanTree_makeFromFrequencies in lodepng.c in LodePNG through 2019-09-28, as used in WinPR in FreeRDP and other products, has a memory leak because a supplied realloc pointer (i.e., the first argument to realloc) is also used for a realloc return value.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
freerdp2fixed2.0.0~git20190204.1.2693389a+dfsg1-2package
freerdp2fixed2.0.0~git20190204.1.2693389a+dfsg1-1+deb10u1busterpackage
freerdpremovedpackage
freerdpnot-affectedstretchpackage

Примечания

  • https://github.com/FreeRDP/FreeRDP/issues/5645

  • https://github.com/FreeRDP/FreeRDP/commit/9fee4ae076b1ec97b97efb79ece08d1dab4df29a (v2.0.0)

  • Multiple source packages embed a copy of lodepng (openscad, tbb, mame, passage,

  • quakespasm, simbody, paraview, dart, drumgizmo, doxygen, love, libtcod, f

  • cubicsdr, nestopia, refind, zopfli, montage), but don't seem security-relevant

  • embedded from: https://github.com/FreeRDP/FreeRDP/commit/1c345834079f3c8b581204e36b0cf0f3c021c445 (2.0.0-beta1+android10)

  • to: https://github.com/FreeRDP/FreeRDP/commit/605b6b6233e52151d208b7faa87691533a857b07 (3.0.0-beta2)

EPSS

Процентиль: 74%
0.00827
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 6 лет назад

HuffmanTree_makeFromFrequencies in lodepng.c in LodePNG through 2019-09-28, as used in WinPR in FreeRDP and other products, has a memory leak because a supplied realloc pointer (i.e., the first argument to realloc) is also used for a realloc return value.

CVSS3: 7.5
nvd
больше 6 лет назад

HuffmanTree_makeFromFrequencies in lodepng.c in LodePNG through 2019-09-28, as used in WinPR in FreeRDP and other products, has a memory leak because a supplied realloc pointer (i.e., the first argument to realloc) is also used for a realloc return value.

github
больше 3 лет назад

HuffmanTree_makeFromFrequencies in lodepng.c in LodePNG through 2019-09-28, as used in WinPR in FreeRDP and other products, has a memory leak because a supplied realloc pointer (i.e., the first argument to realloc) is also used for a realloc return value.

suse-cvrf
около 6 лет назад

Security update for freerdp

suse-cvrf
около 6 лет назад

Security update for freerdp

EPSS

Процентиль: 74%
0.00827
Низкий