PT-2019-1466 · Rdesktop+2 · Rdesktop+2

Eyal Itkin

·

Published

2019-01-18

·

Updated

2024-06-15

·

CVE-2018-8799

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions rdesktop versions up to and including v1.8.3
Description The issue is related to an Out-Of-Bounds Read in the process secondary order() function, which can result in a Denial of Service (segfault). This can be exploited by a remote attacker to cause a disruption in service. The vulnerability is associated with the implementation of the process secondary order function in the RDP client.
Recommendations For rdesktop versions up to and including v1.8.3, consider applying a patch or update when available to fix the Out-Of-Bounds Read issue in the process secondary order() function. As a temporary workaround, restrict access to the process secondary order() function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Buffer Over-read

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-2898
ALT-PU-2020-1636
BDU:2019-00856
CVE-2018-8799
DLA-1683-1
DSA-4394-1
MGASA-2019-0041
OPENSUSE-SU-2019:2135-1
OPENSUSE-SU-2019_2135-1
OPENSUSE-SU-2024:11298-1

Affected Products

Alt Linux
Suse
Rdesktop