Описание
FreeRDP prior to version 2.0.0-rc4 contains an Out-Of-Bounds Write of up to 4 bytes in function nsc_rle_decode() that results in a memory corruption and possibly even a remote code execution.
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | released | 1.1.0~git20140921.1.440916e+dfsg1-15ubuntu1.18.04.1 |
| cosmic | released | 1.1.0~git20140921.1.440916e+dfsg1-15ubuntu1.18.10.1 |
| devel | DNE | |
| disco | DNE | |
| esm-apps/bionic | released | 1.1.0~git20140921.1.440916e+dfsg1-15ubuntu1.18.04.1 |
| esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was not-affected [code not present]] |
| esm-infra/xenial | released | 1.1.0~git20140921.1.440916e+dfsg1-5ubuntu1.3 |
| precise/esm | DNE | |
| trusty | not-affected | code not present |
| trusty/esm | DNE | trusty was not-affected [code not present] |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | released | 2.0.0~git20170725.1.1648deb+dfsg1-7ubuntu0.1 |
| cosmic | released | 2.0.0~git20180411.1.7a7b1802+dfsg1-2ubuntu0.1 |
| devel | released | 2.0.0~git20181120.1.e21b72c95+dfsg1-1 |
| disco | released | 2.0.0~git20181120.1.e21b72c95+dfsg1-1 |
| esm-infra-legacy/trusty | DNE | |
| esm-infra/bionic | released | 2.0.0~git20170725.1.1648deb+dfsg1-7ubuntu0.1 |
| precise/esm | DNE | |
| trusty | DNE | |
| trusty/esm | DNE | |
| upstream | released | 2.0.0~git20181120.1.e21b72c95+dfsg1-1 |
Показывать по
EPSS
7.5 High
CVSS2
9.8 Critical
CVSS3
Связанные уязвимости
FreeRDP prior to version 2.0.0-rc4 contains an Out-Of-Bounds Write of up to 4 bytes in function nsc_rle_decode() that results in a memory corruption and possibly even a remote code execution.
FreeRDP prior to version 2.0.0-rc4 contains an Out-Of-Bounds Write of up to 4 bytes in function nsc_rle_decode() that results in a memory corruption and possibly even a remote code execution.
FreeRDP prior to version 2.0.0-rc4 contains an Out-Of-Bounds Write of ...
FreeRDP prior to version 2.0.0-rc4 contains an Out-Of-Bounds Write of up to 4 bytes in function nsc_rle_decode() that results in a memory corruption and possibly even a remote code execution.
Уязвимость функции nsc_rle_decode() RDP-клиента FreeRDP, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код
EPSS
7.5 High
CVSS2
9.8 Critical
CVSS3