PT-2019-1458 · Rdesktop+2 · Rdesktop+2
Eyal Itkin
·
Published
2019-01-18
·
Updated
2024-06-15
·
CVE-2018-8792
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
rdesktop versions up to and including v1.8.3
Description
The issue is related to the implementation of the
cssp read tsrequest function in the RDP client, which is associated with an out-of-bounds memory read. This can be exploited by a remote attacker to cause a denial of service, resulting in a crash.Recommendations
For rdesktop versions up to and including v1.8.3, consider disabling the
cssp read tsrequest function as a temporary workaround until a patch is available.Fix
DoS
Buffer Over-read
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Suse
Rdesktop