PT-2020-5624 · Freerdp+4 · Freerdp+4
Lowakallabeth
·
Published
2020-06-22
·
Updated
2024-06-15
·
CVE-2020-4032
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
FreeRDP versions prior to 2.1.2
Description
The issue is related to an integer casting vulnerability in the update recv secondary order function of the FreeRDP protocol implementation. This vulnerability affects all clients with +glyph-cache /relax-order-checks enabled. The vulnerability is associated with a lack of proper data type conversion mechanism in the gdi SelectObject component, which may allow a remote attacker to impact data integrity.
Recommendations
For versions prior to 2.1.2, update to version 2.1.2 to resolve the issue. As a temporary workaround, consider disabling the +glyph-cache /relax-order-checks feature until the update is applied.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Freerdp
Linuxmint
Suse
Ubuntu