CVE-2018-8789: High severity FreeRDP freerdp vulnerability
FreeRDP prior to version 2.0.0-rc4 contains several Out-Of-Bounds Reads in the NTLM Authentication module that results in a Denial of Service (segfault).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-8789?
CVE-2018-8789 is classified as a Denial of Service vulnerability due to out-of-bounds reads that can lead to a segmentation fault.
How do I fix CVE-2018-8789?
To fix CVE-2018-8789, upgrade FreeRDP to version 2.3.0+dfsg1-2+deb11u1 or 2.10.0+dfsg1-1 or later.
Which versions of FreeRDP are affected by CVE-2018-8789?
FreeRDP versions prior to 2.0.0-rc4 are affected by CVE-2018-8789, including all 2.0.0 release candidates and earlier.
What types of systems are impacted by CVE-2018-8789?
CVE-2018-8789 affects systems running vulnerable versions of FreeRDP, including specific Debian and Ubuntu Linux distributions.
What are the consequences of not addressing CVE-2018-8789?
Failure to address CVE-2018-8789 may result in unexpected crashes and service disruptions due to the Denial of Service vulnerability.