Directory traversal vulnerability in the disk_create function in disk.c in rdesktop before 1.7.0, when disk redirection is enabled, allows remote RDP servers to read or overwrite arbitrary files via a .. (dot dot) in a pathname.
CVSS Details
- CVSS 3.1 Base Score: 9.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade rdesktop | Dec 1, 2016 | May 24, 2011 |
| Debian | — | Upgrade rdesktop | Jul 30, 2024 | May 24, 2011 |
| Gentoo Linux | — | Upgrade net-misc/rdesktop. | Oct 30, 2017 | May 24, 2011 |
| Oracle_linux | — | Upgrade rdesktop | Oct 16, 2024 | May 24, 2011 |
| Suse | — | Upgrade rdesktop | Feb 17, 2015 | May 24, 2011 |
| Ubuntu | — | Upgrade rdesktop | Nov 8, 2024 | May 24, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub