RDesktop version 1.8.4 contains multiple out-of-bound access read vulnerabilities in its code, which results in a denial of service (DoS) condition. This attack appear to be exploitable via network connectivity. These issues have been fixed in version 1.8.5
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade rdesktop | Nov 5, 2019 | Oct 30, 2019 |
| Oracle Solaris | — | Upgrade desktop/remote-desktop/rdesktop to version 1.8.6-11.4.16.0.1.3.0 on Solaris 11.4 | Dec 18, 2019 | Oct 30, 2019 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Oct 30, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub