First published: Fri May 29 2020(Updated: )
In FreeRDP less than or equal to 2.0.0, by providing manipulated input a malicious client can create a double free condition and crash the server. This is fixed in version 2.1.0.
Credit: security-advisories@github.com security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
FreeRDP FreeRDP | <2.1.0 | |
openSUSE Leap | =15.1 | |
Debian Debian Linux | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2020-11017.
The severity of CVE-2020-11017 is medium with a severity value of 6.5.
A malicious client can exploit CVE-2020-11017 by providing manipulated input, which can lead to a double free condition and crash the server.
FreeRDP versions less than or equal to 2.0.0 are affected by CVE-2020-11017.
To fix the vulnerability CVE-2020-11017, update to version 2.1.0 of FreeRDP.