First published: Mon Jun 22 2020(Updated: )
In FreeRDP before version 2.1.2, an out of bound reads occurs resulting in accessing a memory location that is outside of the boundaries of the static array PRIMARY_DRAWING_ORDER_FIELD_BYTES. This is fixed in version 2.1.2.
Credit: security-advisories@github.com security-advisories@github.com security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
FreeRDP FreeRDP | <2.1.2 | |
Fedoraproject Fedora | =31 | |
Fedoraproject Fedora | =32 | |
openSUSE Leap | =15.1 | |
Canonical Ubuntu Linux | =18.04 | |
Canonical Ubuntu Linux | =20.04 | |
Debian Debian Linux | =10.0 | |
debian/freerdp2 | 2.3.0+dfsg1-2+deb11u1 2.10.0+dfsg1-1 2.11.7+dfsg1-4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-11095 is a vulnerability in FreeRDP before version 2.1.2 that allows for out-of-bound reads resulting in accessing a memory location outside of the boundaries of the static array PRIMARY_DRAWING_ORDER_FIELD_BYTES.
The severity of CVE-2020-11095 is medium with a CVSS score of 5.4.
To fix CVE-2020-11095, update FreeRDP to version 2.1.2 or later.
FreeRDP versions before 2.1.2 are affected by CVE-2020-11095.
More information about CVE-2020-11095 can be found on the CVE website (cve.mitre.org), the FreeRDP GitHub repository, and the FreeRDP website.