CVE-2020-11042

MEDIUM

FreeRDP >1.1-<2.0.0 - Memory Corruption

Title source: llm
STIX 2.1

Description

In FreeRDP greater than 1.1 and before 2.0.0, there is an out-of-bounds read in update_read_icon_info. It allows reading a attacker-defined amount of client memory (32bit unsigned -> 4GB) to an intermediate buffer. This can be used to crash the client or store information for later retrieval. This has been patched in 2.0.0.

Scores

CVSS v3 5.5
EPSS 0.0013
EPSS Percentile 31.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:L

Details

CWE
CWE-125
Status published
Products (7)
canonical/ubuntu_linux 16.04
canonical/ubuntu_linux 18.04
canonical/ubuntu_linux 19.10
canonical/ubuntu_linux 20.04
debian/debian_linux 9.0
debian/debian_linux 10.0
freerdp/freerdp 1.1.0 - 2.0.0
Published May 07, 2020
Tracked Since Feb 18, 2026