PT-2020-3474 · Freerdp+6 · Freerdp+6
Bmiklautz
·
Published
2020-04-09
·
Updated
2024-06-15
·
CVE-2020-11524
CVSS v2.0
8.5
High
| Vector | AV:N/AC:M/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
FreeRDP versions > 1.0 through 2.0.0-rc4
Description
The issue is related to an out-of-bounds write operation in the memory buffer of the FreeRDP client. This can be exploited by a remote attacker to cause a denial of service. The problem is specifically located in the
libfreerdp/codec/interleaved.c file.Recommendations
For FreeRDP versions > 1.0 through 2.0.0-rc4, consider disabling the affected
interleaved.c codec until a patch is available to prevent potential exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Centos
Freerdp
Linuxmint
Red Hat
Suse
Ubuntu