PT-2020-6920 · Freerdp+6 · Freerdp+6

Bmiklautz

·

Published

2020-04-09

·

Updated

2023-10-24

·

CVE-2020-11047

CVSS v2.0

6.2

Medium

VectorAV:N/AC:H/Au:M/C:C/I:N/A:C
Name of the Vulnerable Software and Affected Versions FreeRDP versions 1.1 through 1.9
Description The issue is related to an out-of-bounds read in the autodetect recv bandwidth measure results function. A malicious server can extract up to 8 bytes of client memory with a manipulated message by providing a short input and reading the measurement result data.
Recommendations For versions prior to 2.0.0, update to version 2.0.0 to resolve the issue. As a temporary workaround, consider restricting access to the autodetect recv bandwidth measure results function until a patch is available.

Exploit

Fix

Out of bounds Read

Weakness Enumeration

Related Identifiers

ALSA-2020:4647
BDU:2023-07126
CESA-2020_4031
CESA-2020_4647
CVE-2020-11047
DLA-3606-1
GHSA-9FW6-M2Q8-H5PW
MGASA-2020-0297
RHSA-2020:4031
RHSA-2020:4647
RHSA-2020_4031
RHSA-2020_4647
RLSA-2020:4647
USN-4379-1

Affected Products

Almalinux
Centos
Freerdp
Linuxmint
Red Hat
Rocky Linux
Ubuntu