First published: Fri May 29 2020(Updated: )
In FreeRDP less than or equal to 2.0.0, when using a manipulated server with USB redirection enabled (nearly) arbitrary memory can be read and written due to integer overflows in length checks. This has been patched in 2.1.0.
Credit: security-advisories@github.com security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
FreeRDP FreeRDP | <2.1.0 | |
openSUSE Leap | =15.1 | |
Debian Debian Linux | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-11039 is a vulnerability in FreeRDP version 2.0.0 and below that allows arbitrary memory read and write due to integer overflows in length checks.
CVE-2020-11039 works by exploiting integer overflows in length checks when using a manipulated server with USB redirection enabled.
FreeRDP versions up to and including 2.0.0 are affected by CVE-2020-11039.
CVE-2020-11039 has a severity level of 6.8 (high).
You can fix CVE-2020-11039 by updating to FreeRDP version 2.1.0 or later.