CVE-2018-8786: Buffer Overflow
FreeRDP prior to version 2.0.0-rc4 contains an Integer Truncation that leads to a Heap-Based Buffer Overflow in function updatereadbitmapupdate() and results in a memory corruption and probably even a remote code execution.
Other sources
FreeRDP prior to version 2.0.0-rc4 contains an Integer Truncation that leads to a Heap-Based Buffer Overflow in function updatereadbitmapupdate() and results in a memory corruption.
Upstream patch:
https://github.com/FreeRDP/FreeRDP/commit/445a5a42c500ceb80f8fa7f2c11f3682538033f3
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-8786?
CVE-2018-8786 has a high severity due to the potential for remote code execution and memory corruption.
How do I fix CVE-2018-8786?
To fix CVE-2018-8786, update FreeRDP to version 2.0.0-rc4 or later.
What systems are affected by CVE-2018-8786?
CVE-2018-8786 affects FreeRDP versions prior to 2.0.0-rc4 along with various older versions of Linux distributions that include FreeRDP.
What type of vulnerability is CVE-2018-8786?
CVE-2018-8786 is classified as an integer truncation vulnerability leading to a heap-based buffer overflow.
Is there any known exploit for CVE-2018-8786?
While there are no specific public exploits reported for CVE-2018-8786, its nature suggests high risk if left unpatched.