CVE Vulnerabilities

CVE-2020-11524

Out-of-bounds Write

Published: May 15, 2020 | Modified: Jul 27, 2020
CVSS 3.x
6.6
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6 MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
6.6 IMPORTANT
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Ubuntu

libfreerdp/codec/interleaved.c in FreeRDP versions > 1.0 through 2.0.0-rc4 has an Out-of-bounds Write.

Weakness

The software writes data past the end, or before the beginning, of the intended buffer.

Affected Software

Name Vendor Start Version End Version
Freerdp Freerdp * *
Freerdp Freerdp 2.0.0 2.0.0
Freerdp Freerdp 2.0.0 2.0.0
Freerdp Freerdp 2.0.0 2.0.0
Freerdp Freerdp 2.0.0 2.0.0
Freerdp Freerdp 2.0.0 2.0.0
Freerdp Freerdp 2.0.0 2.0.0
Red Hat Enterprise Linux 7 RedHat freerdp-0:2.0.0-4.rc4.el7_8 *
Red Hat Enterprise Linux 8 RedHat freerdp-2:2.0.0-46.rc4.el8_2.1 *
Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions RedHat freerdp-2:2.0.0-46.rc4.el8_0.1 *
Red Hat Enterprise Linux 8.1 Extended Update Support RedHat freerdp-2:2.0.0-46.rc4.el8_1.1 *
Freerdp Ubuntu trusty *
Freerdp2 Ubuntu bionic *
Freerdp2 Ubuntu eoan *
Freerdp2 Ubuntu focal *
Freerdp2 Ubuntu trusty *

Potential Mitigations

  • Use a language that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid.

  • For example, many languages that perform their own memory management, such as Java and Perl, are not subject to buffer overflows. Other languages, such as Ada and C#, typically provide overflow protection, but the protection can be disabled by the programmer.

  • Be wary that a language’s interface to native code may still be subject to overflows, even if the language itself is theoretically safe.

  • Use a vetted library or framework that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid.

  • Examples include the Safe C String Library (SafeStr) by Messier and Viega [REF-57], and the Strsafe.h library from Microsoft [REF-56]. These libraries provide safer versions of overflow-prone string-handling functions.

  • Run or compile the software using features or extensions that automatically provide a protection mechanism that mitigates or eliminates buffer overflows.

  • For example, certain compilers and extensions provide automatic buffer overflow detection mechanisms that are built into the compiled code. Examples include the Microsoft Visual Studio /GS flag, Fedora/Red Hat FORTIFY_SOURCE GCC flag, StackGuard, and ProPolice.

  • Consider adhering to the following rules when allocating and managing an application’s memory:

  • Run or compile the software using features or extensions that randomly arrange the positions of a program’s executable and libraries in memory. Because this makes the addresses unpredictable, it can prevent an attacker from reliably jumping to exploitable code.

  • Examples include Address Space Layout Randomization (ASLR) [REF-58] [REF-60] and Position-Independent Executables (PIE) [REF-64].

References