Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-13398

Опубликовано: 22 мая 2020
Источник: redhat
CVSS3: 8.3
EPSS Низкий

Описание

An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) write vulnerability has been detected in crypto_rsa_common in libfreerdp/crypto/crypto.c.

An issue was found in freerdp's libfreerdp/crypto/crypto.c, in versions before 2.1.1, where buffer access with an incorrect length value, leads to an out-of-bounds write. This flaw allows a remote, unauthenticated, attacker running an RDP server, or a local attacker, using a specially crafted certificate, to cause an out-of-bounds write into client process memory, corrupting the integrity of the data used in the RSA encryption functionality, or causing a denial of service.

Меры по смягчению последствий

To mitigate this flaw, only make connection attempts to trusted RDP servers from the RDP client application.

Дополнительная информация

Статус:

Important
Дефект:
CWE-805->CWE-122->CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=1841199freerdp: Out-of-bounds write in crypto_rsa_common in libfreerdp/crypto/crypto.c

EPSS

Процентиль: 63%
0.00455
Низкий

8.3 High

CVSS3

Связанные уязвимости

CVSS3: 8.3
ubuntu
больше 5 лет назад

An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) write vulnerability has been detected in crypto_rsa_common in libfreerdp/crypto/crypto.c.

CVSS3: 8.3
nvd
больше 5 лет назад

An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) write vulnerability has been detected in crypto_rsa_common in libfreerdp/crypto/crypto.c.

CVSS3: 8.3
debian
больше 5 лет назад

An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB ...

CVSS3: 8.3
github
больше 3 лет назад

An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) write vulnerability has been detected in crypto_rsa_common in libfreerdp/crypto/crypto.c.

oracle-oval
больше 5 лет назад

ELSA-2020-2407: freerdp security update (IMPORTANT)

EPSS

Процентиль: 63%
0.00455
Низкий

8.3 High

CVSS3