FreeRDP prior to version 2.0.0-rc4 contains an Integer Truncation that leads to a Heap-Based Buffer Overflow in function update_read_bitmap_update() and results in a memory corruption and probably even a remote code execution.
When converting from one data type to another, such as long to integer, data can be omitted or translated in a way that produces unexpected values. If the resulting values are used in a sensitive context, then dangerous behaviors may occur.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Freerdp | Freerdp | * | 1.2.0 (including) |
Freerdp | Freerdp | 2.0.0-rc1 (including) | 2.0.0-rc1 (including) |
Freerdp | Freerdp | 2.0.0-rc2 (including) | 2.0.0-rc2 (including) |
Freerdp | Freerdp | 2.0.0-rc3 (including) | 2.0.0-rc3 (including) |
Red Hat Enterprise Linux 7 | RedHat | freerdp-0:1.0.2-15.el7_6.1 | * |
Freerdp | Ubuntu | bionic | * |
Freerdp | Ubuntu | cosmic | * |
Freerdp | Ubuntu | trusty | * |
Freerdp | Ubuntu | xenial | * |
Freerdp2 | Ubuntu | bionic | * |
Freerdp2 | Ubuntu | cosmic | * |
Freerdp2 | Ubuntu | devel | * |
Freerdp2 | Ubuntu | disco | * |
Freerdp2 | Ubuntu | upstream | * |