CVE-2020-11019: Out of bound read in update_recv in FreeRDP
Published May 29, 2020
·Updated
In FreeRDP less than or equal to 2.0.0, when running with logger set to "WLOGTRACE", a possible crash of application could occur due to a read of an invalid array index. Data could be printed as string to local terminal. This has been fixed in 2.1.0.
Affected Software
3 affected components
FreeRDP freerdp<2.1.0
openSUSE Leap=15.1
Debian Debian Linux=10.0
Event History
May 29, 2020
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2020-11019.
2
What is the severity of CVE-2020-11019?
The severity of CVE-2020-11019 is medium with a score of 6.5.
3
How does CVE-2020-11019 affect FreeRDP?
CVE-2020-11019 affects FreeRDP versions less than or equal to 2.0.0.
4
What is the impact of CVE-2020-11019?
CVE-2020-11019 could cause a possible crash of the application and data could be printed as a string to the local terminal.
5
How can I fix CVE-2020-11019?
To fix CVE-2020-11019, update FreeRDP to version 2.1.0 or later.