CVE-2020-11097: OOB read in ntlm_av_pair_get in FreeRDP
Published Jun 22, 2020
·Updated
In FreeRDP before version 2.1.2, an out of bounds read occurs resulting in accessing a memory location that is outside of the boundaries of the static array PRIMARYDRAWINGORDERFIELDBYTES. This is fixed in version 2.1.2.
Affected Software
8 affected componentsFixes available
FreeRDP freerdp<2.1.2
Fedoraproject Fedora=31
Fedoraproject Fedora=32
openSUSE Leap=15.1
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=20.04
Debian Debian Linux=10.0
debian/freerdp2
2.3.0+dfsg1-2+deb11u12.3.0+dfsg1-2+deb11u32.11.7+dfsg1-6~deb12u1
Remediation
Event History
Jun 22, 2020
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Feb 23, 2026
Data Sourced
via Ubuntu·06:30 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·06:30 PM
DescriptionAffected Software
Data Sourced
via Launchpad·06:31 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-11097?
The severity of CVE-2020-11097 is medium with a CVSS score of 5.4.
2
What is the impact of CVE-2020-11097?
CVE-2020-11097 can lead to an out of bounds read resulting in accessing a memory location outside of the boundaries of the static array.
3
How can I fix CVE-2020-11097?
To fix CVE-2020-11097, upgrade to FreeRDP version 2.1.2 or later.
4
Where can I find more information about CVE-2020-11097?
You can find more information about CVE-2020-11097 on the MITRE CVE website, FreeRDP's GitHub security advisories, and the FreeRDP blog.
5
What is the CWE ID of CVE-2020-11097?
The CWE ID of CVE-2020-11097 is 125.