CVE-2017-2836: Medium severity freerdp vulnerability
An exploitable denial of service vulnerability exists within the reading of proprietary server certificates in FreeRDP 2.0.0-beta1+android11. A specially crafted challenge packet can cause the program termination leading to a denial of service condition. An attacker can compromise the server or use man in the middle to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-2836?
The severity of CVE-2017-2836 is classified as a denial of service vulnerability that can lead to program termination.
How do I fix CVE-2017-2836?
To fix CVE-2017-2836, upgrade to a patched version of FreeRDP that resolves the vulnerability.
Who is affected by CVE-2017-2836?
CVE-2017-2836 affects users of FreeRDP version 2.0.0-beta1 and certain Debian Linux distributions.
What causes the denial of service in CVE-2017-2836?
The denial of service in CVE-2017-2836 is caused by processing specially crafted challenge packets that lead to program termination.
Is CVE-2017-2836 exploitable remotely?
Yes, CVE-2017-2836 is exploitable remotely if an attacker can send the crafted challenge packets to the affected FreeRDP server.