CVE Vulnerabilities

CVE-2017-2839

Published: Apr 24, 2018 | Modified: Jun 03, 2022
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
5.3 LOW
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H
Ubuntu
LOW

An exploitable denial of service vulnerability exists within the handling of challenge packets in FreeRDP 2.0.0-beta1+android11. A specially crafted challenge packet can cause the program termination leading to a denial of service condition. An attacker can compromise the server or use man in the middle to trigger this vulnerability.

Affected Software

Name Vendor Start Version End Version
Freerdp Freerdp 2.0.0-beta1 (including) 2.0.0-beta1 (including)
Freerdp Ubuntu devel *
Freerdp Ubuntu trusty *
Freerdp Ubuntu upstream *
Freerdp Ubuntu xenial *
Freerdp Ubuntu zesty *

References