CVE-2020-4030: OOB read in `TrioParse` in FreeRDP
In FreeRDP before version 2.1.2, there is an out of bounds read in TrioParse. Logging might bypass string length checks due to an integer overflow. This is fixed in version 2.1.2.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-4030?
CVE-2020-4030 is a vulnerability in FreeRDP before version 2.1.2 that allows an out of bounds read in TrioParse, which can bypass string length checks.
What is the severity of CVE-2020-4030?
The severity of CVE-2020-4030 is medium, with a severity value of 6.5.
How does CVE-2020-4030 affect FreeRDP?
CVE-2020-4030 affects FreeRDP versions before 2.1.2, allowing for an out of bounds read in TrioParse.
Is there a fix for CVE-2020-4030?
Yes, the vulnerability is fixed in FreeRDP version 2.1.2.
Where can I find more information about CVE-2020-4030?
You can find more information about CVE-2020-4030 at the MITRE CVE database (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-4030), the FreeRDP security advisories on GitHub (https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-fjr5-97f5-qq98), and the FreeRDP website (http://www.freerdp.com/2020/06/22/2_1_2-released).