CVE-2020-11099: OOB Read in license_read_new_or_upgrade_license_packet in FreeRDP
In FreeRDP before version 2.1.2, there is an out of bounds read in licensereadneworupgradelicensepacket. A manipulated license packet can lead to out of bound reads to an internal buffer. This is fixed in version 2.1.2.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-11099?
CVE-2020-11099 is a vulnerability in FreeRDP that allows for an out of bounds read in the license packet, leading to potential buffer overflow.
What is the severity of CVE-2020-11099?
CVE-2020-11099 has a severity rating of medium with a CVSS score of 6.5.
How does CVE-2020-11099 affect FreeRDP?
CVE-2020-11099 affects FreeRDP versions before 2.1.2, allowing for an out of bounds read in the license packet.
How can I fix CVE-2020-11099?
To fix CVE-2020-11099, update to FreeRDP version 2.1.2 or later.
Where can I find more information about CVE-2020-11099?
More information about CVE-2020-11099 can be found at the MITRE CVE database (link: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11099) and the FreeRDP security advisories page (link: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-977w-866x-4v5h).