CVE-2018-8788: Critical severity FreeRDP freerdp vulnerability
FreeRDP prior to version 2.0.0-rc4 contains an Out-Of-Bounds Write of up to 4 bytes in function nscrledecode() that results in a memory corruption and possibly even a remote code execution.
Other sources
FreeRDP prior to version 2.0.0-rc4 contains an Out-Of-Bounds Write of up to 4 bytes in function nscrledecode() that results in a memory corruption.
Upstream patch:
https://github.com/FreeRDP/FreeRDP/commit/d1112c279bd1a327e8e4d0b5f371458bf2579659
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-8788?
CVE-2018-8788 is classified as a high severity vulnerability due to its potential for memory corruption and remote code execution.
How do I fix CVE-2018-8788?
To fix CVE-2018-8788, upgrade FreeRDP to version 2.0.0-rc4 or later.
What software is affected by CVE-2018-8788?
CVE-2018-8788 affects FreeRDP versions prior to 2.0.0-rc4, including several release candidates and earlier stable versions.
What type of vulnerability is CVE-2018-8788?
CVE-2018-8788 is an Out-Of-Bounds Write vulnerability that can lead to memory corruption.
Can CVE-2018-8788 allow for remote code execution?
Yes, CVE-2018-8788 can potentially allow for remote code execution due to the memory corruption caused by the vulnerability.