Integer signedness error in the xrealloc function (rdesktop.c) in RDesktop 1.5.0 allows remote attackers to execute arbitrary code via unknown parameters that trigger a heap-based overflow. NOTE: the role of the channel_process function was not specified by the original researcher.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade rdesktop | Dec 1, 2016 | May 12, 2008 |
| Debian | — | Upgrade rdesktop | Jul 30, 2024 | May 12, 2008 |
| Gentoo Linux | — | Upgrade net-misc/rdesktop. | Oct 30, 2017 | May 12, 2008 |
| Oracle_linux | — | Upgrade rdesktop | Oct 16, 2024 | May 12, 2008 |
| Suse | — | Upgrade suse-releaseUpgrade rdesktop | Feb 17, 2015 | May 12, 2008 |
| Ubuntu | — | Upgrade rdesktop | Nov 8, 2024 | May 12, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub