PT-2020-6921 · Freerdp+6 · Freerdp+6

Bmiklautz

·

Published

2020-03-31

·

Updated

2023-10-24

·

CVE-2020-11044

CVSS v2.0

3.5

Low

VectorAV:N/AC:M/Au:S/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions FreeRDP versions 1.2 through 1.2 (simplified to) FreeRDP versions greater than 1.2 and before 2.0.0
Description The issue is related to a double free error in the update read cache bitmap v3 order function of the FreeRDP RDP client. This error can be exploited by a remote attacker to cause a denial of service. The exploitation occurs when the client parses corrupted data from a manipulated server.
Recommendations For FreeRDP versions greater than 1.2 and before 2.0.0, update to version 2.0.0 to resolve the issue. As a temporary workaround, consider restricting access to the update read cache bitmap v3 order function until a patch is available.

Exploit

Fix

Double Free

Weakness Enumeration

Related Identifiers

ALSA-2020:4647
BDU:2023-07127
CESA-2020_4031
CESA-2020_4647
CVE-2020-11044
DLA-3606-1
GHSA-CGQH-P732-6X2W
MGASA-2020-0297
OESA-2021-1008
RHSA-2020:4031
RHSA-2020:4647
RHSA-2020_4031
RHSA-2020_4647
RLSA-2020:4647
USN-4379-1

Affected Products

Almalinux
Centos
Freerdp
Linuxmint
Red Hat
Rocky Linux
Ubuntu