Описание
In FreeRDP after 1.1 and before 2.0.0, there is an out-of-bounds read in autodetect_recv_bandwidth_measure_results. A malicious server can extract up to 8 bytes of client memory with a manipulated message by providing a short input and reading the measurement result data. This has been patched in 2.0.0.
Релиз | Статус | Примечание |
---|---|---|
bionic | not-affected | code not present |
devel | DNE | |
eoan | DNE | |
esm-apps/bionic | not-affected | code not present |
esm-infra-legacy/trusty | DNE | |
esm-infra/focal | DNE | |
esm-infra/xenial | not-affected | code not present |
focal | DNE | |
precise/esm | DNE | |
trusty | ignored | end of standard support |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
bionic | released | 2.1.1+dfsg1-0ubuntu0.18.04.1 |
devel | not-affected | 2.1.1+dfsg1-1 |
eoan | released | 2.1.1+dfsg1-0ubuntu0.19.10.1 |
esm-infra-legacy/trusty | DNE | |
esm-infra/bionic | not-affected | 2.1.1+dfsg1-0ubuntu0.18.04.1 |
esm-infra/focal | not-affected | 2.1.1+dfsg1-0ubuntu0.20.04.1 |
focal | released | 2.1.1+dfsg1-0ubuntu0.20.04.1 |
precise/esm | DNE | |
trusty | ignored | end of standard support |
trusty/esm | DNE |
Показывать по
4.9 Medium
CVSS2
5.5 Medium
CVSS3
Связанные уязвимости
In FreeRDP after 1.1 and before 2.0.0, there is an out-of-bounds read in autodetect_recv_bandwidth_measure_results. A malicious server can extract up to 8 bytes of client memory with a manipulated message by providing a short input and reading the measurement result data. This has been patched in 2.0.0.
In FreeRDP after 1.1 and before 2.0.0, there is an out-of-bounds read in autodetect_recv_bandwidth_measure_results. A malicious server can extract up to 8 bytes of client memory with a manipulated message by providing a short input and reading the measurement result data. This has been patched in 2.0.0.
In FreeRDP after 1.1 and before 2.0.0, there is an out-of-bounds read ...
Уязвимость функции autodetect_recv_bandwidth_measure_results) RDP-клиента FreeRDP, позволяющая нарушителю раскрыть защищаемую информацию или вызвать отказ в обслуживании
Moderate: freerdp and vinagre security, bug fix, and enhancement update
4.9 Medium
CVSS2
5.5 Medium
CVSS3