CVE-2018-8784: Buffer Overflow
Published Nov 29, 2018
·Updated
FreeRDP prior to version 2.0.0-rc4 contains a Heap-Based Buffer Overflow in function zgfxdecompresssegment() that results in a memory corruption and probably even a remote code execution.
Affected Software
7 affected componentsFixes available
FreeRDP freerdp<=1.2.0
FreeRDP freerdp=2.0.0-rc1
FreeRDP freerdp=2.0.0-rc2
FreeRDP freerdp=2.0.0-rc3
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=18.10
debian/freerdp2
2.3.0+dfsg1-2+deb11u12.3.0+dfsg1-2+deb11u32.11.7+dfsg1-6~deb12u1
Remediation
Event History
Nov 29, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionWeakness
Jan 11, 2024
Data Sourced
via Launchpad·11:10 PM
Description
Feb 20, 2026
Data Sourced
via Ubuntu·09:15 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·09:15 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-8784?
CVE-2018-8784 has a high severity rating due to its potential for remote code execution.
2
How do I fix CVE-2018-8784?
To fix CVE-2018-8784, upgrade FreeRDP to version 2.0.0-rc4 or later.
3
What versions of FreeRDP are affected by CVE-2018-8784?
CVE-2018-8784 affects FreeRDP versions prior to 2.0.0-rc4.
4
What types of attacks can exploit CVE-2018-8784?
CVE-2018-8784 can be exploited via heap-based buffer overflow leading to memory corruption and potential remote code execution.
5
Is CVE-2018-8784 present in Ubuntu distributions?
Yes, CVE-2018-8784 can affect FreeRDP installations on certain versions of Ubuntu, particularly those using affected FreeRDP versions.