CVE-2018-8789

HIGH

FreeRDP <2.0.0-rc4 - DoS

Title source: llm

Description

FreeRDP prior to version 2.0.0-rc4 contains several Out-Of-Bounds Reads in the NTLM Authentication module that results in a Denial of Service (segfault).

Scores

CVSS v3 7.5
EPSS 0.0165
EPSS Percentile 81.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Classification

CWE
CWE-125 CWE-126
Status published

Affected Products (9)

freerdp/freerdp < 1.2.0
freerdp/freerdp
freerdp/freerdp
freerdp/freerdp
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
debian/debian_linux

Timeline

Published Nov 29, 2018
Tracked Since Feb 18, 2026