CVE-2020-11017: Double free in cliprdr_server_receive_capabilities in FreeRDP
Published May 29, 2020
·Updated
In FreeRDP less than or equal to 2.0.0, by providing manipulated input a malicious client can create a double free condition and crash the server. This is fixed in version 2.1.0.
Affected Software
3 affected components
FreeRDP freerdp<2.1.0
openSUSE Leap=15.1
Debian Debian Linux=10.0
Event History
May 29, 2020
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-11017.
2
What is the severity of CVE-2020-11017?
The severity of CVE-2020-11017 is medium with a severity value of 6.5.
3
How can a malicious client exploit CVE-2020-11017?
A malicious client can exploit CVE-2020-11017 by providing manipulated input, which can lead to a double free condition and crash the server.
4
Which versions of FreeRDP are affected by CVE-2020-11017?
FreeRDP versions less than or equal to 2.0.0 are affected by CVE-2020-11017.
5
How can I fix the vulnerability CVE-2020-11017?
To fix the vulnerability CVE-2020-11017, update to version 2.1.0 of FreeRDP.