ISOMAN

CVE

CVE-2020-11049

In FreeRDP after 1.1 and before 2.0.0, there is an out-of-bound read of client memory that is then passed on to the protocol parser. This has been patched in 2.0.0.

Severity
MEDIUM
CVSS
5.5
Published
Modified

Linked Releases

DistributionReleaseStatusEvidence
Ubuntu20.04.6 amd64 desktopunknownsource
Ubuntu20.04.6 amd64 live-serverunknownsource

References

  1. https://github.com/FreeRDP/FreeRDP/commit/c367f65d42e0d2e1ca248998175180aa9c2eacd0
  2. https://github.com/FreeRDP/FreeRDP/issues/6008
  3. https://github.com/FreeRDP/FreeRDP/pull/6019
  4. https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-wwh7-r2r8-xjpr
  5. https://lists.debian.org/debian-lts-announce/2023/10/msg00008.html
  6. https://usn.ubuntu.com/4379-1/
  7. https://usn.ubuntu.com/4382-1/
  8. https://github.com/FreeRDP/FreeRDP/commit/c367f65d42e0d2e1ca248998175180aa9c2eacd0
  9. https://github.com/FreeRDP/FreeRDP/issues/6008
  10. https://github.com/FreeRDP/FreeRDP/pull/6019
  11. https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-wwh7-r2r8-xjpr
  12. https://lists.debian.org/debian-lts-announce/2023/10/msg00008.html
  13. https://usn.ubuntu.com/4379-1/
  14. https://usn.ubuntu.com/4382-1/