First published: Fri May 29 2020(Updated: )
In FreeRDP less than or equal to 2.0.0, there is an out-of-bounds read in rfx_process_message_tileset. Invalid data fed to RFX decoder results in garbage on screen (as colors). This has been patched in 2.1.0.
Credit: security-advisories@github.com security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
FreeRDP FreeRDP | <2.1.0 | |
openSUSE Leap | =15.1 | |
Debian Debian Linux | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-11043 is a vulnerability in FreeRDP that allows an out-of-bounds read in the rfx_process_message_tileset function.
The severity of CVE-2020-11043 is medium with a severity value of 2.7.
CVE-2020-11043 affects FreeRDP versions up to and including 2.0.0.
You can fix CVE-2020-11043 by updating FreeRDP to version 2.1.0 or later.
You can find more information about CVE-2020-11043 at the following references: [http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00080.html](http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00080.html), [https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-5mr4-28w3-rc84](https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-5mr4-28w3-rc84), [https://lists.debian.org/debian-lts-announce/2023/10/msg00008.html](https://lists.debian.org/debian-lts-announce/2023/10/msg00008.html)