CVE-2020-11042: Out-of-bounds Read in FreeRDP
In FreeRDP greater than 1.1 and before 2.0.0, there is an out-of-bounds read in updatereadiconinfo. It allows reading a attacker-defined amount of client memory (32bit unsigned -> 4GB) to an intermediate buffer. This can be used to crash the client or store information for later retrieval. This has been patched in 2.0.0.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-11042?
The severity of CVE-2020-11042 is medium (5.9).
What is the affected software for CVE-2020-11042?
The affected software for CVE-2020-11042 includes FreeRDP versions greater than 1.1 and before 2.0.0.
How can an attacker exploit CVE-2020-11042?
An attacker can exploit CVE-2020-11042 by performing an out-of-bounds read in update_read_icon_info, allowing them to read a potentially large amount of client memory.
How can I fix CVE-2020-11042?
To fix CVE-2020-11042, update FreeRDP to version 2.0.0 or above.
Where can I find more information about CVE-2020-11042?
You can find more information about CVE-2020-11042 at the following references: [CVE-2020-11042](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11042), [FreeRDP Advisory GHSA-9jp6-5vf2-cx2q](https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-9jp6-5vf2-cx2q), [Ubuntu Security Notice USN-4379-1](https://ubuntu.com/security/notices/USN-4379-1).