Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-13398

Опубликовано: 22 мая 2020
Источник: redhat
CVSS3: 8.3
EPSS Низкий

Описание

An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) write vulnerability has been detected in crypto_rsa_common in libfreerdp/crypto/crypto.c.

An issue was found in freerdp's libfreerdp/crypto/crypto.c, in versions before 2.1.1, where buffer access with an incorrect length value, leads to an out-of-bounds write. This flaw allows a remote, unauthenticated, attacker running an RDP server, or a local attacker, using a specially crafted certificate, to cause an out-of-bounds write into client process memory, corrupting the integrity of the data used in the RSA encryption functionality, or causing a denial of service.

Меры по смягчению последствий

To mitigate this flaw, only make connection attempts to trusted RDP servers from the RDP client application.

Дополнительная информация

Статус:

Important
Дефект:
CWE-805
https://bugzilla.redhat.com/show_bug.cgi?id=1841199freerdp: Out-of-bounds write in crypto_rsa_common in libfreerdp/crypto/crypto.c

EPSS

Процентиль: 82%
0.02325
Низкий

8.3 High

CVSS3

Связанные уязвимости

CVSS3: 8.3
ubuntu
около 6 лет назад

An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) write vulnerability has been detected in crypto_rsa_common in libfreerdp/crypto/crypto.c.

CVSS3: 8.3
nvd
около 6 лет назад

An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) write vulnerability has been detected in crypto_rsa_common in libfreerdp/crypto/crypto.c.

CVSS3: 8.3
debian
около 6 лет назад

An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB ...

CVSS3: 8.3
github
около 4 лет назад

An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) write vulnerability has been detected in crypto_rsa_common in libfreerdp/crypto/crypto.c.

oracle-oval
около 6 лет назад

ELSA-2020-2407: freerdp security update (IMPORTANT)

EPSS

Процентиль: 82%
0.02325
Низкий

8.3 High

CVSS3