First published: Mon May 12 2008(Updated: )
Integer underflow in the iso_recv_msg function (iso.c) in rdesktop 1.5.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a Remote Desktop Protocol (RDP) request with a small length field.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ubuntu Desktop File Utils | =1.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-1801 has a severity rating that indicates it may lead to significant denial of service and potentially arbitrary code execution.
To fix CVE-2008-1801, upgrade to a version of rdesktop that has patched the vulnerability.
CVE-2008-1801 enables remote attackers to cause a denial of service crash and may lead to arbitrary code execution.
CVE-2008-1801 specifically affects rdesktop version 1.5.0.
The cause of CVE-2008-1801 is an integer underflow in the iso_recv_msg function within rdesktop.