First published: Mon Jun 22 2020(Updated: )
In FreeRDP before version 2.1.2, there is a global OOB read in update_read_cache_bitmap_v3_order. As a workaround, one can disable bitmap cache with -bitmap-cache (default). This is fixed in version 2.1.2.
Credit: security-advisories@github.com security-advisories@github.com security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
FreeRDP FreeRDP | <2.1.2 | |
Fedoraproject Fedora | =31 | |
Fedoraproject Fedora | =32 | |
openSUSE Leap | =15.1 | |
Canonical Ubuntu Linux | =18.04 | |
Canonical Ubuntu Linux | =20.04 | |
Debian Debian Linux | =10.0 | |
debian/freerdp2 | 2.3.0+dfsg1-2+deb11u1 2.10.0+dfsg1-1 2.11.7+dfsg1-4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this FreeRDP vulnerability is CVE-2020-11096.
The severity rating of CVE-2020-11096 is medium.
One can mitigate the CVE-2020-11096 vulnerability by disabling bitmap cache with the -bitmap-cache flag.
The affected software for CVE-2020-11096 includes FreeRDP versions before 2.1.2.
You can find more information about CVE-2020-11096 on the CVE Mitre website, the FreeRDP GitHub security advisory page, and the FreeRDP blog post announcing version 2.1.2.