CVE-2017-2835: High severity freerdp vulnerability
An exploitable code execution vulnerability exists in the RDP receive functionality of FreeRDP 2.0.0-beta1+android11. A specially crafted server response can cause an out-of-bounds write resulting in an exploitable condition. An attacker can compromise the server or use a man in the middle to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-2835?
CVE-2017-2835 has a high severity rating due to its potential for code execution through specially crafted responses.
How do I fix CVE-2017-2835?
To fix CVE-2017-2835, update FreeRDP to a version that is not affected by this vulnerability.
What software versions are vulnerable to CVE-2017-2835?
FreeRDP version 2.0.0-beta1 is vulnerable to CVE-2017-2835 on Debian GNU/Linux versions 8.0 and 9.0.
Can CVE-2017-2835 be exploited remotely?
Yes, CVE-2017-2835 can be exploited remotely by an attacker who sends a specially crafted server response.
What are the potential impacts of CVE-2017-2835?
The potential impacts of CVE-2017-2835 include unauthorized code execution, leading to a full compromise of the affected system.