ISOMAN

CVE

CVE-2020-4030

In FreeRDP before version 2.1.2, there is an out of bounds read in TrioParse. Logging might bypass string length checks due to an integer overflow. This is fixed in version 2.1.2.

Severity
LOW
CVSS
3.5
Published
Modified

Linked Releases

DistributionReleaseStatusEvidence
Ubuntu20.04.6 amd64 desktopunknownsource
Ubuntu20.04.6 amd64 live-serverunknownsource

References

  1. http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00080.html
  2. http://www.freerdp.com/2020/06/22/2_1_2-released
  3. https://github.com/FreeRDP/FreeRDP/commit/05cd9ea2290d23931f615c1b004d4b2e69074e27
  4. https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-fjr5-97f5-qq98
  5. https://lists.debian.org/debian-lts-announce/2023/10/msg00008.html
  6. https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6Y35HBHG2INICLSGCIKNAR7GCXEHQACQ/
  7. https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XOZLH35OJWIQLM7FYDXAP2EAUBDXE76V/
  8. https://usn.ubuntu.com/4481-1/
  9. http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00080.html
  10. http://www.freerdp.com/2020/06/22/2_1_2-released
  11. https://github.com/FreeRDP/FreeRDP/commit/05cd9ea2290d23931f615c1b004d4b2e69074e27
  12. https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-fjr5-97f5-qq98
  13. https://lists.debian.org/debian-lts-announce/2023/10/msg00008.html
  14. https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6Y35HBHG2INICLSGCIKNAR7GCXEHQACQ/
  15. https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XOZLH35OJWIQLM7FYDXAP2EAUBDXE76V/
  16. https://usn.ubuntu.com/4481-1/