CVE-2020-13398: High severity FreeRDP freerdp vulnerability
Published May 22, 2020
·Updated
An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) write vulnerability has been detected in cryptorsacommon in libfreerdp/crypto/crypto.c.
Affected Software
11 affected componentsFixes available
FreeRDP freerdp<2.1.1
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=19.10
Canonical Ubuntu Linux=20.04
Debian Debian Linux=9.0
Debian Debian Linux=10.0
openSUSE Leap=15.1
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
debian/freerdp2
2.3.0+dfsg1-2+deb11u12.3.0+dfsg1-2+deb11u32.11.7+dfsg1-6~deb12u1
Remediation
Event History
May 22, 2020
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Jan 11, 2024
Data Sourced
via Launchpad·11:39 PM
Description
Feb 22, 2026
Data Sourced
via Ubuntu·03:44 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·03:46 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-13398?
CVE-2020-13398 is classified as a high severity vulnerability due to its potential for out-of-bounds write attacks.
2
How do I fix CVE-2020-13398?
To mitigate CVE-2020-13398, upgrade FreeRDP to version 2.1.1 or later.
3
Which versions of FreeRDP are affected by CVE-2020-13398?
FreeRDP versions prior to 2.1.1 are vulnerable to CVE-2020-13398.
4
Is CVE-2020-13398 present in Ubuntu distributions?
Yes, CVE-2020-13398 affects various Ubuntu versions prior to their respective patched releases.
5
Can CVE-2020-13398 be exploited remotely?
Yes, CVE-2020-13398 can be exploited remotely, allowing attackers to execute arbitrary code.