Back

MEDIUM

Out-of-bound read in FreeRDP

Published May 29, 2020

Description

In FreeRDP before 2.1.0, there is an out-of-bound read in irp functions (parallel_process_irp_create, serial_process_irp_create, drive_process_irp_write, printer_process_irp_write, rdpei_recv_pdu, serial_process_irp_write). This has been fixed in 2.1.0.

Affected products

Remediation

Red Hat mitigation

The vulnerability is associated with the use of the command line options: /drive, +multitouch, /paralell, /printer, and /servial. To mitigate this vulnerability, do not use these commands.

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published May 29, 2020
Updated Aug 4, 2024
Reserved Mar 30, 2020
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date May 29, 2020