CVE-2019-17178: High severity freerdp vulnerability
HuffmanTreemakeFromFrequencies in lodepng.c in LodePNG through 2019-09-28, as used in WinPR in FreeRDP and other products, has a memory leak because a supplied realloc pointer (i.e., the first argument to realloc) is also used for a realloc return value.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-17178?
CVE-2019-17178 is rated as a medium severity vulnerability due to the potential for memory leaks.
How do I fix CVE-2019-17178?
To fix CVE-2019-17178, users should upgrade to a patched version of FreeRDP or LodePNG that addresses the memory leak issue.
Which versions are affected by CVE-2019-17178?
CVE-2019-17178 affects FreeRDP versions up to 1.0.2 and 1.1.0-beta1, as well as LodePNG versions up to 2019-09-28.
What is the exploitability of CVE-2019-17178?
While CVE-2019-17178 may lead to increased memory consumption, it is less likely to be directly exploitable for arbitrary code execution.
Is CVE-2019-17178 related to specific operating systems?
Yes, CVE-2019-17178 is particularly relevant for users of openSUSE versions 15.0 and 15.1.