rdesktop versions up to and including v1.8.3 contain an Integer Underflow that leads to a Heap-Based Buffer Overflow in the function lspci_process() and results in memory corruption and probably even a remote code execution.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-rdesktop | Aug 22, 2024 | Mar 15, 2019 | |
| Arch Linux | arch-linux-upgrade-latest | Jul 11, 2025 | Mar 15, 2019 | |
| Debian | debian-upgrade-rdesktop | Feb 20, 2019 | Feb 18, 2019 | |
| Freebsd | freebsd-upgrade-package-rdesktop | Feb 23, 2019 | Feb 22, 2019 | |
| Gentoo Linux | gentoo-linux-upgrade-net-misc-rdesktop | Mar 11, 2019 | Mar 10, 2019 | |
| Oracle Solaris | oracle-solaris-11-4-upgrade-desktop-remote-desktop-rdesktop-1-8-4-11-4-14-0-1-1-0 | Oct 16, 2019 | Mar 15, 2019 | |
| Redhat_linux | — | no-fix-redhat-rpm-package | Jul 9, 2025 | Mar 15, 2019 |
| Suse | — | suse-upgrade-rdesktop | Sep 17, 2019 | Jan 2, 2019 |
| Ubuntu | no-fix-ubuntu-package | Jun 26, 2025 | Mar 15, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub