CVE-2020-11044: Double Free in FreeRDP
Published May 7, 2020
·Updated
In FreeRDP greater than 1.2 and before 2.0.0, a double free in updatereadcachebitmapv3order crashes the client application if corrupted data from a manipulated server is parsed. This has been patched in 2.0.0.
Affected Software
6 affected componentsFixes available
FreeRDP freerdp>1.2.0<2.0.0
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=19.10
Canonical Ubuntu Linux=20.04
debian/freerdp2
2.3.0+dfsg1-2+deb11u12.3.0+dfsg1-2+deb11u32.10.0+dfsg1-1
Debian Debian Linux=10.0
Remediation
Event History
May 7, 2020
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Jan 11, 2024
Data Sourced
via Launchpad·11:36 PM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·02:20 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2020-11044?
CVE-2020-11044 is a vulnerability in FreeRDP that allows a double free in update_read_cache_bitmap_v3_order to crash the client application if corrupted data from a manipulated server is parsed.
2
How severe is CVE-2020-11044?
CVE-2020-11044 has a severity rating of 2.2 (low).
3
How can I fix CVE-2020-11044?
Update to FreeRDP version 2.0.0 or higher, which includes the patch for CVE-2020-11044.
4
Where can I find more information about CVE-2020-11044?
You can find more information about CVE-2020-11044 on the MITRE CVE website and the FreeRDP GitHub security advisory.
5
Is Ubuntu affected by CVE-2020-11044?
Yes, Ubuntu versions 18.04, 19.10, and 20.04 are affected by CVE-2020-11044.