CVE Vulnerabilities

CVE-2014-0791

Published: Jan 03, 2014 | Modified: Aug 30, 2020
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
6.8 MODERATE
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
LOW

Integer overflow in the license_read_scope_list function in libfreerdp/core/license.c in FreeRDP through 1.0.2 allows remote RDP servers to cause a denial of service (application crash) or possibly have unspecified other impact via a large ScopeCount value in a Scope List in a Server License Request packet.

Affected Software

Name Vendor Start Version End Version
Freerdp Freerdp 1.0.0 (including) 1.0.0 (including)
Freerdp Freerdp 1.0.1 (including) 1.0.1 (including)
Freerdp Freerdp 1.0.2 (including) 1.0.2 (including)
Freerdp Ubuntu devel *
Freerdp Ubuntu precise *
Freerdp Ubuntu quantal *
Freerdp Ubuntu raring *
Freerdp Ubuntu saucy *
Freerdp Ubuntu trusty *
Freerdp Ubuntu utopic *
Freerdp Ubuntu vivid *
Freerdp Ubuntu wily *
Freerdp Ubuntu xenial *
Freerdp Ubuntu yakkety *
Freerdp Ubuntu zesty *

References