CVE-2020-11095: Global OOB read in update_recv_primary_order in FreeRDP
In FreeRDP before version 2.1.2, an out of bound reads occurs resulting in accessing a memory location that is outside of the boundaries of the static array PRIMARYDRAWINGORDERFIELDBYTES. This is fixed in version 2.1.2.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-11095?
CVE-2020-11095 is a vulnerability in FreeRDP before version 2.1.2 that allows for out-of-bound reads resulting in accessing a memory location outside of the boundaries of the static array PRIMARY_DRAWING_ORDER_FIELD_BYTES.
What is the severity of CVE-2020-11095?
The severity of CVE-2020-11095 is medium with a CVSS score of 5.4.
How can I fix CVE-2020-11095?
To fix CVE-2020-11095, update FreeRDP to version 2.1.2 or later.
Which software versions are affected by CVE-2020-11095?
FreeRDP versions before 2.1.2 are affected by CVE-2020-11095.
Where can I find more information about CVE-2020-11095?
More information about CVE-2020-11095 can be found on the CVE website (cve.mitre.org), the FreeRDP GitHub repository, and the FreeRDP website.