CVE-2020-11526: Integer Overflow
Published May 15, 2020
·Updated
Last updated 25 August 2025
Other sources
libfreerdp/core/update.c in FreeRDP versions > 1.1 through 2.0.0-rc4 has an Out-of-bounds Read.
— Launchpad
Affected Software
14 affected componentsFixes available
FreeRDP freerdp>1.1.0<2.0.0
FreeRDP freerdp=2.0.0
FreeRDP freerdp=2.0.0-rc0
FreeRDP freerdp=2.0.0-rc1
FreeRDP freerdp=2.0.0-rc2
FreeRDP freerdp=2.0.0-rc3
FreeRDP freerdp=2.0.0-rc4
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=19.10
Canonical Ubuntu Linux=20.04
openSUSE Leap=15.1
Debian Debian Linux=9.0
debian/freerdp2
2.3.0+dfsg1-2+deb11u12.3.0+dfsg1-2+deb11u32.11.7+dfsg1-6~deb12u1
Remediation
Patch Available
Event History
May 15, 2020
CVE Published
via MITRE·04:18 PM
Data Sourced
via MITRE·04:18 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·11:35 PM
Description
Feb 22, 2026
Data Sourced
via Ubuntu·03:44 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·03:45 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-11526?
CVE-2020-11526 has been classified with a high severity due to the potential for an out-of-bounds read, which could be exploited in certain circumstances.
2
How do I fix CVE-2020-11526?
To fix CVE-2020-11526, upgrade FreeRDP to version 2.3.0+dfsg1-2+deb11u1 or 2.10.0+dfsg1-1, or apply patches provided by your operating system vendor.
3
Which versions of FreeRDP are affected by CVE-2020-11526?
FreeRDP versions greater than 1.1 up to 2.0.0-rc4 are affected by CVE-2020-11526.
4
Is CVE-2020-11526 a remote code execution vulnerability?
No, CVE-2020-11526 is an out-of-bounds read vulnerability and does not directly allow for remote code execution.
5
What platforms are impacted by CVE-2020-11526?
CVE-2020-11526 affects multiple platforms including Debian, Ubuntu, and openSUSE where FreeRDP is installed.