Описание
Security update for freerdp
This update for freerdp fixes the following issues:
- CVE-2013-4118: Added a NULL pointer check to fix a server crash (bsc#829013).
- CVE-2014-0791: Integer overflow in the license_read_scope_list function in libfreerdp/core/license.c in FreeRDP allowed remote RDP servers to cause a denial of service (application crash) or possibly have unspecified other impact via a large ScopeCount value in a Scope List in a Server License Request packet. (bsc#857491)
- CVE-2014-0250: Multiple integer overflows in client/X11/xf_graphics.c in FreeRDP allowed remote attackers to have an unspecified impact via the width and height to the (1) xf_Pointer_New or (2) xf_Bitmap_Decompress function, which causes an incorrect amount of memory to be allocated. (bsc#880317)
Список пакетов
SUSE Linux Enterprise Desktop 12 SP1
SUSE Linux Enterprise Software Development Kit 12 SP1
SUSE Linux Enterprise Workstation Extension 12 SP1
Ссылки
- Link for SUSE-SU-2016:2506-1
- E-Mail link for SUSE-SU-2016:2506-1
- SUSE Security Ratings
- SUSE Bug 829013
- SUSE Bug 857491
- SUSE Bug 880317
- SUSE CVE CVE-2013-4118 page
- SUSE CVE CVE-2014-0250 page
- SUSE CVE CVE-2014-0791 page
Описание
FreeRDP before 1.1.0-beta1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via unspecified vectors.
Затронутые продукты
Ссылки
- CVE-2013-4118
- SUSE Bug 829013
Описание
Multiple integer overflows in client/X11/xf_graphics.c in FreeRDP allow remote attackers to have an unspecified impact via the width and height to the (1) xf_Pointer_New or (2) xf_Bitmap_Decompress function, which causes an incorrect amount of memory to be allocated.
Затронутые продукты
Ссылки
- CVE-2014-0250
- SUSE Bug 880317
- SUSE Bug 975218
Описание
Integer overflow in the license_read_scope_list function in libfreerdp/core/license.c in FreeRDP through 1.0.2 allows remote RDP servers to cause a denial of service (application crash) or possibly have unspecified other impact via a large ScopeCount value in a Scope List in a Server License Request packet.
Затронутые продукты
Ссылки
- CVE-2014-0791
- SUSE Bug 857491
- SUSE Bug 975218