CVE-2020-11018: Out of bound read in cliprdr_server_receive_capabilities in FreeRDP
Published May 29, 2020
·Updated
In FreeRDP less than or equal to 2.0.0, a possible resource exhaustion vulnerability can be performed. Malicious clients could trigger out of bound reads causing memory allocation with random size. This has been fixed in 2.1.0.
Affected Software
3 affected components
FreeRDP freerdp<=2.0.0
openSUSE Leap=15.1
Debian Debian Linux=10.0
Event History
May 29, 2020
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-11018?
CVE-2020-11018 has a medium severity level due to the potential for resource exhaustion and memory issues.
2
How do I fix CVE-2020-11018?
To fix CVE-2020-11018, upgrade FreeRDP to version 2.1.0 or higher.
3
Which versions of FreeRDP are affected by CVE-2020-11018?
CVE-2020-11018 affects FreeRDP versions less than or equal to 2.0.0.
4
What are the potential risks associated with CVE-2020-11018?
The potential risks include memory allocation issues and the possibility of out-of-bounds read vulnerabilities.
5
Is CVE-2020-11018 fixed in any specific releases?
Yes, CVE-2020-11018 is fixed in FreeRDP version 2.1.0.