Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-2834

Опубликовано: 24 июл. 2017
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

An exploitable code execution vulnerability exists in the authentication functionality of FreeRDP 2.0.0-beta1+android11. A specially crafted server response can cause an out-of-bounds write resulting in an exploitable condition. An attacker can compromise the server or use a man in the middle attack to trigger this vulnerability.

Отчет

Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6freerdpWill not fix
Red Hat Enterprise Linux 7freerdpWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-129
https://bugzilla.redhat.com/show_bug.cgi?id=1475224freerdp: Out-of-bounds write in license_recv()

EPSS

Процентиль: 77%
0.01071
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7
ubuntu
почти 8 лет назад

An exploitable code execution vulnerability exists in the authentication functionality of FreeRDP 2.0.0-beta1+android11. A specially crafted server response can cause an out-of-bounds write resulting in an exploitable condition. An attacker can compromise the server or use a man in the middle attack to trigger this vulnerability.

CVSS3: 7
nvd
почти 8 лет назад

An exploitable code execution vulnerability exists in the authentication functionality of FreeRDP 2.0.0-beta1+android11. A specially crafted server response can cause an out-of-bounds write resulting in an exploitable condition. An attacker can compromise the server or use a man in the middle attack to trigger this vulnerability.

CVSS3: 7
debian
почти 8 лет назад

An exploitable code execution vulnerability exists in the authenticati ...

CVSS3: 7
github
больше 3 лет назад

An exploitable code execution vulnerability exists in the authentication functionality of FreeRDP 2.0.0-beta1+android11. A specially crafted server response can cause an out-of-bounds write resulting in an exploitable condition. An attacker can compromise the server or use a man in the middle attack to trigger this vulnerability.

suse-cvrf
больше 8 лет назад

Security update for freerdp

EPSS

Процентиль: 77%
0.01071
Низкий

7.5 High

CVSS3