First published: Tue Apr 24 2018(Updated: )
An exploitable denial of service vulnerability exists within the reading of proprietary server certificates in FreeRDP 2.0.0-beta1+android11. A specially crafted challenge packet can cause the program termination leading to a denial of service condition. An attacker can compromise the server or use man in the middle to trigger this vulnerability.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/freerdp | ||
FreeRDP | =2.0.0-beta1 | |
Debian | =8.0 | |
Debian | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-2836 is classified as a denial of service vulnerability that can lead to program termination.
To fix CVE-2017-2836, upgrade to a patched version of FreeRDP that resolves the vulnerability.
CVE-2017-2836 affects users of FreeRDP version 2.0.0-beta1 and certain Debian Linux distributions.
The denial of service in CVE-2017-2836 is caused by processing specially crafted challenge packets that lead to program termination.
Yes, CVE-2017-2836 is exploitable remotely if an attacker can send the crafted challenge packets to the affected FreeRDP server.