CVE Vulnerabilities

CVE-2014-0791

Published: Jan 03, 2014 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
6.8 MODERATE
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
LOW

Integer overflow in the license_read_scope_list function in libfreerdp/core/license.c in FreeRDP through 1.0.2 allows remote RDP servers to cause a denial of service (application crash) or possibly have unspecified other impact via a large ScopeCount value in a Scope List in a Server License Request packet.

Affected Software

Name Vendor Start Version End Version
Freerdp Freerdp 1.0.0 (including) 1.0.0 (including)
Freerdp Freerdp 1.0.1 (including) 1.0.1 (including)
Freerdp Freerdp 1.0.2 (including) 1.0.2 (including)
Freerdp Ubuntu devel *
Freerdp Ubuntu precise *
Freerdp Ubuntu quantal *
Freerdp Ubuntu raring *
Freerdp Ubuntu saucy *
Freerdp Ubuntu trusty *
Freerdp Ubuntu utopic *
Freerdp Ubuntu vivid *
Freerdp Ubuntu wily *
Freerdp Ubuntu xenial *
Freerdp Ubuntu yakkety *
Freerdp Ubuntu zesty *

References