CVE-2018-20174: High severity ubuntu desktop file utils vulnerability
Published Mar 15, 2019
·Updated
rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in the function uicliphandledata() that results in an information leak.
Affected Software
2 affected componentsFixes available
debian/rdesktop
1.8.6-21.9.0-2
rdesktop RDesktop<=1.8.3
Remediation
Event History
Mar 15, 2019
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-20174?
CVE-2018-20174 is classified as a low-severity vulnerability due to its information leak characteristics.
2
How do I fix CVE-2018-20174?
To fix CVE-2018-20174, upgrade rdesktop to version 1.8.6-2 or later.
3
What software versions are affected by CVE-2018-20174?
CVE-2018-20174 affects rdesktop versions up to and including 1.8.3.
4
What is the nature of the vulnerability in CVE-2018-20174?
CVE-2018-20174 is an Out-Of-Bounds Read vulnerability in the ui_clip_handle_data() function.
5
Is there a workaround for CVE-2018-20174?
There is no official workaround for CVE-2018-20174; upgrading the software is the recommended course of action.