PT-2019-1458 · Rdesktop+2 · Rdesktop+2
Eyal Itkin
·
Publicado
2019-01-18
·
Atualizado
2024-06-15
·
CVE-2018-8792
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
rdesktop versions up to and including v1.8.3
Description
The issue is related to the implementation of the
cssp read tsrequest function in the RDP client, which is associated with an out-of-bounds memory read. This can be exploited by a remote attacker to cause a denial of service, resulting in a crash.Recommendations
For rdesktop versions up to and including v1.8.3, consider disabling the
cssp read tsrequest function as a temporary workaround until a patch is available.Correção
DoS
Buffer Over-read
Out of bounds Read
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Suse
Rdesktop