Description
In FreeRDP after 1.1 and before 2.0.0, there is an out-of-bounds read in autodetect_recv_bandwidth_measure_results. A malicious server can extract up to 8 bytes of client memory with a manipulated message by providing a short input and reading the measurement result data. This has been patched in 2.0.0.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3606-1 | freerdp2 security update |
EUVD |
EUVD-2020-3431 | In FreeRDP after 1.1 and before 2.0.0, there is an out-of-bounds read in autodetect_recv_bandwidth_measure_results. A malicious server can extract up to 8 bytes of client memory with a manipulated message by providing a short input and reading the measurement result data. This has been patched in 2.0.0. |
Ubuntu USN |
USN-4379-1 | FreeRDP vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-04T11:21:14.613Z
Reserved: 2020-03-30T00:00:00.000Z
Link: CVE-2020-11047
No data.
Status : Modified
Published: 2020-05-07T20:15:12.127
Modified: 2024-11-21T04:56:40.517
Link: CVE-2020-11047
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD
Ubuntu USN