PT-2019-1458 · Rdesktop+2 · Rdesktop+2

Eyal Itkin

·

Published

2019-01-18

·

Updated

2024-06-15

·

CVE-2018-8792

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions rdesktop versions up to and including v1.8.3
Description The issue is related to the implementation of the cssp read tsrequest function in the RDP client, which is associated with an out-of-bounds memory read. This can be exploited by a remote attacker to cause a denial of service, resulting in a crash.
Recommendations For rdesktop versions up to and including v1.8.3, consider disabling the cssp read tsrequest function as a temporary workaround until a patch is available.

Fix

DoS

Buffer Over-read

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-2898
ALT-PU-2020-1636
BDU:2019-00848
CVE-2018-8792
DLA-1683-1
DSA-4394-1
MGASA-2019-0041
OPENSUSE-SU-2019:2135-1
OPENSUSE-SU-2019_2135-1
OPENSUSE-SU-2024:11298-1

Affected Products

Alt Linux
Suse
Rdesktop