CVE-2020-11096: Global OOB read in update_read_cache_bitmap_v3_order in FreeRDP
Published Jun 22, 2020
·Updated
In FreeRDP before version 2.1.2, there is a global OOB read in updatereadcachebitmapv3order. As a workaround, one can disable bitmap cache with -bitmap-cache (default). This is fixed in version 2.1.2.
Affected Software
8 affected componentsFixes available
FreeRDP freerdp<2.1.2
Fedoraproject Fedora=31
Fedoraproject Fedora=32
openSUSE Leap=15.1
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=20.04
Debian Debian Linux=10.0
debian/freerdp2
2.3.0+dfsg1-2+deb11u12.3.0+dfsg1-2+deb11u32.11.7+dfsg1-6~deb12u1
Remediation
Event History
Jun 22, 2020
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Feb 23, 2026
Data Sourced
via Ubuntu·06:30 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·06:30 PM
DescriptionAffected Software
Data Sourced
via Launchpad·06:31 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this FreeRDP vulnerability?
The vulnerability ID for this FreeRDP vulnerability is CVE-2020-11096.
2
What is the severity rating of CVE-2020-11096?
The severity rating of CVE-2020-11096 is medium.
3
How can I mitigate the CVE-2020-11096 vulnerability?
One can mitigate the CVE-2020-11096 vulnerability by disabling bitmap cache with the -bitmap-cache flag.
4
What is the affected software for CVE-2020-11096?
The affected software for CVE-2020-11096 includes FreeRDP versions before 2.1.2.
5
Where can I find more information about CVE-2020-11096?
You can find more information about CVE-2020-11096 on the CVE Mitre website, the FreeRDP GitHub security advisory page, and the FreeRDP blog post announcing version 2.1.2.