Описание
In FreeRDP less than or equal to 2.0.0, there is an out-of-bound read in ntlm_read_AuthenticateMessage. This has been fixed in 2.1.0.
Ссылки
- Third Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- Mailing ListThird Party Advisory
- Third Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- Mailing ListThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.1.0 (исключая)
cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*
Конфигурация 3
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
EPSS
Процентиль: 42%
0.0019
Низкий
3.1 Low
CVSS3
5.4 Medium
CVSS3
5.5 Medium
CVSS2
Дефекты
CWE-125
CWE-125
Связанные уязвимости
CVSS3: 3.1
ubuntu
около 5 лет назад
In FreeRDP less than or equal to 2.0.0, there is an out-of-bound read in ntlm_read_AuthenticateMessage. This has been fixed in 2.1.0.
CVSS3: 5.4
redhat
около 5 лет назад
In FreeRDP less than or equal to 2.0.0, there is an out-of-bound read in ntlm_read_AuthenticateMessage. This has been fixed in 2.1.0.
CVSS3: 3.1
debian
около 5 лет назад
In FreeRDP less than or equal to 2.0.0, there is an out-of-bound read ...
rocky
больше 4 лет назад
Moderate: freerdp and vinagre security, bug fix, and enhancement update
oracle-oval
больше 4 лет назад
ELSA-2020-4647: freerdp and vinagre security, bug fix, and enhancement update (MODERATE)
EPSS
Процентиль: 42%
0.0019
Низкий
3.1 Low
CVSS3
5.4 Medium
CVSS3
5.5 Medium
CVSS2
Дефекты
CWE-125
CWE-125