CVE-2018-8787: Integer Overflow
FreeRDP prior to version 2.0.0-rc4 contains an Integer Overflow that leads to a Heap-Based Buffer Overflow in function gdiBitmapDecompress() and results in a memory corruption and probably even a remote code execution.
Other sources
FreeRDP prior to version 2.0.0-rc4 contains an Integer Overflow that leads to a Heap-Based Buffer Overflow in function gdiBitmapDecompress() and results in a memory corruption.
Upstream patch:
https://github.com/FreeRDP/FreeRDP/commit/09b9d4f1994a674c4ec85b4947aa656eda1aed8a
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-8787?
CVE-2018-8787 has a critical severity rating due to its potential for memory corruption and remote code execution.
How do I fix CVE-2018-8787?
To fix CVE-2018-8787, upgrade FreeRDP to version 2.0.0-rc4 or later.
Which versions of FreeRDP are affected by CVE-2018-8787?
FreeRDP versions prior to 2.0.0-rc4 are affected by CVE-2018-8787.
Is CVE-2018-8787 applicable to Ubuntu and Red Hat systems?
Yes, CVE-2018-8787 affects FreeRDP installations on both Ubuntu and Red Hat systems prior to the specified fix versions.
What is the attack vector for CVE-2018-8787?
CVE-2018-8787 can be exploited remotely through crafted requests processed by the vulnerable FreeRDP service.