PT-2020-5402 · Freerdp+6 · Freerdp+6
Lowbmiklautz
·
Published
2020-05-10
·
Updated
2023-10-20
·
CVE-2020-11089
CVSS v2.0
6.0
Medium
| Vector | AV:N/AC:M/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
FreeRDP versions prior to 2.1.0
Description
The issue is related to an out-of-bound read in irp functions, specifically in
parallel process irp create, serial process irp create, drive process irp write, printer process irp write, rdpei recv pdu, and serial process irp write. This can potentially allow a remote attacker to impact the confidentiality, integrity, and availability of protected information.Recommendations
For FreeRDP versions prior to 2.1.0, update to version 2.1.0 to resolve the issue. As a temporary workaround, consider disabling the affected irp functions until a patch is available. Restrict access to the vulnerable components to minimize the risk of exploitation. Avoid using the vulnerable functions in the affected versions until the issue is resolved.
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Almalinux
Centos
Freerdp
Red Hat
Rocky Linux
Suse