CVE-2018-8794: Integer Overflow
rdesktop versions up to and including v1.8.3 contain an Integer Overflow that leads to an Out-Of-Bounds Write in function processbitmapupdates() and results in a memory corruption and possibly even a remote code execution.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-8794?
CVE-2018-8794 is classified as a critical vulnerability due to the potential for remote code execution and memory corruption.
How do I fix CVE-2018-8794?
To fix CVE-2018-8794, update rdesktop to version 1.8.6-2 or later, or 1.9.0-2 or later depending on your system.
What will happen if I leave CVE-2018-8794 unpatched?
Leaving CVE-2018-8794 unpatched may allow an attacker to exploit the integer overflow, leading to memory corruption and potentially taking control of the affected system.
Which versions of rdesktop are affected by CVE-2018-8794?
Versions of rdesktop up to and including v1.8.3 are affected by CVE-2018-8794.
Is CVE-2018-8794 present in Debian Linux distributions?
Yes, CVE-2018-8794 affects Debian Linux versions 8.0 and 9.0 when using the vulnerable rdesktop package.