PT-2017-15570 · Freerdp+2 · Freerdp+2
Tyler Bohan
·
Published
2017-07-27
·
Updated
2024-06-15
·
CVE-2017-2836
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
FreeRDP versions 2.0.0-beta1+android11
Description
A denial of service issue exists due to the improper handling of proprietary server certificates. An attacker can send a specially crafted challenge packet, causing the program to terminate and resulting in a denial of service condition. This can be triggered by compromising the server or using a man-in-the-middle attack.
Recommendations
For FreeRDP version 2.0.0-beta1+android11, consider restricting access to the certificate reading functionality until a patch is available. As a temporary workaround, implement additional validation on challenge packets to prevent specially crafted packets from causing program termination.
Fix
DoS
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Freerdp
Suse
Ubuntu