PT-2020-5624 · Freerdp+4 · Freerdp+4

Lowakallabeth

·

Published

2020-06-22

·

Updated

2024-06-15

·

CVE-2020-4032

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions FreeRDP versions prior to 2.1.2
Description The issue is related to an integer casting vulnerability in the update recv secondary order function of the FreeRDP protocol implementation. This vulnerability affects all clients with +glyph-cache /relax-order-checks enabled. The vulnerability is associated with a lack of proper data type conversion mechanism in the gdi SelectObject component, which may allow a remote attacker to impact data integrity.
Recommendations For versions prior to 2.1.2, update to version 2.1.2 to resolve the issue. As a temporary workaround, consider disabling the +glyph-cache /relax-order-checks feature until the update is applied.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2225
ALT-PU-2020-2232
BDU:2021-01324
CVE-2020-4032
DLA-3606-1
GHSA-3898-MC89-X2VC
MGASA-2020-0297
OPENSUSE-SU-2020:1090-1
OPENSUSE-SU-2020_1090-1
OPENSUSE-SU-2024:10768-1
SUSE-SU-2020:2032-1
SUSE-SU-2020:2068-1
SUSE-SU-2020:2272-1
USN-4481-1

Affected Products

Alt Linux
Freerdp
Linuxmint
Suse
Ubuntu