CVE-2020-13397: Medium severity FreeRDP freerdp vulnerability
An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) read vulnerability has been detected in securityfipsdecrypt in libfreerdp/core/security.c due to an uninitialized value.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-13397?
The severity of CVE-2020-13397 is medium with a CVSS score of 5.5.
How does CVE-2020-13397 affect FreeRDP?
CVE-2020-13397 affects FreeRDP versions before 2.1.1.
What is the vulnerability in CVE-2020-13397?
CVE-2020-13397 is an out-of-bounds (OOB) read vulnerability in security_fips_decrypt in libfreerdp/core/security.c.
What is the fix for CVE-2020-13397 in Ubuntu?
To fix CVE-2020-13397 in Ubuntu, update the freerdp package to version 2.1.1+dfsg1-0ubuntu0.18.04.1 or later.
Are there any references for CVE-2020-13397?
Yes, you can find more information about CVE-2020-13397 at the following references: [reference 1](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13397), [reference 2](https://github.com/FreeRDP/FreeRDP/commit/8fb6336a4072abcee8ce5bd6ae91104628c7bb69), [reference 3](https://github.com/FreeRDP/FreeRDP/compare/2.1.0...2.1.1).