vulnerability

Oracle Linux: CVE-2020-13398: ELSA-2020-2405: freerdp security update (IMPORTANT) (Multiple Advisories)

Severity
7
CVSS
(AV:N/AC:L/Au:S/C:P/I:P/A:P)
Published
May 22, 2020
Added
Jun 6, 2020
Modified
Dec 3, 2025

Description

An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) write vulnerability has been detected in crypto_rsa_common in libfreerdp/crypto/crypto.c.
An issue was found in freerdp's libfreerdp/crypto/crypto.c, in versions before 2.1.1, where buffer access with an incorrect length value, leads to an out-of-bounds write. This flaw allows a remote, unauthenticated, attacker running an RDP server, or a local attacker, using a specially crafted certificate, to cause an out-of-bounds write into client process memory, corrupting the integrity of the data used in the RSA encryption functionality, or causing a denial of service.

Solutions

oracle-linux-upgrade-freerdporacle-linux-upgrade-freerdp-develoracle-linux-upgrade-freerdp-libsoracle-linux-upgrade-freerdp-pluginsoracle-linux-upgrade-libwinproracle-linux-upgrade-libwinpr-devel
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.