CVE-2020-11098: Out-of-bound read in glyph_cache_put in FreeRDP
In FreeRDP before version 2.1.2, there is an out-of-bound read in glyphcacheput. This affects all FreeRDP clients with +glyph-cache option enabled This is fixed in version 2.1.2.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-11098?
CVE-2020-11098 is a vulnerability in FreeRDP that allows for an out-of-bound read in the glyph_cache_put function.
What is the severity of CVE-2020-11098?
CVE-2020-11098 has a severity level of medium with a score of 6.5.
Which software versions are affected by CVE-2020-11098?
All FreeRDP clients before version 2.1.2 with the +glyph-cache option enabled are affected.
How can I fix CVE-2020-11098?
CVE-2020-11098 can be fixed by updating FreeRDP to version 2.1.2 or newer.
Where can I find more information about CVE-2020-11098?
You can find more information about CVE-2020-11098 at the following references: [CVE-2020-11098](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11098), [GitHub Advisory](https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-jr57-f58x-hjmv), [FreeRDP Release Announcement](http://www.freerdp.com/2020/06/22/2_1_2-released).