HIGH
freerdp: Out-of-bounds read in ntlm_read_ChallengeMessage in winpr/libwinpr/sspi/NTLM/ntlm_message.c.
Published May 22, 2020
7.1
HIGHCVSS 3.1
EPSS 2.34%
Description
An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) read vulnerability has been detected in ntlm_read_ChallengeMessage in winpr/libwinpr/sspi/NTLM/ntlm_message.c.
Affected products
No data.
Configuration 2
OR
- 16.04
- 18.04
- 19.10
- 20.04
- 9.0
- 10.0
- 15.1
No data.
Red Hat Enterprise Linux 7
freerdp-0:2.1.1-2.el7
Fixed · RHSA-2020:4031
Red Hat Enterprise Linux 8
freerdp-2:2.1.1-1.el8
Fixed · RHSA-2020:4647
Red Hat Enterprise Linux 8
vinagre-0:3.22.0-23.el8
Fixed · RHSA-2020:4647
Red Hat Enterprise Linux 6
freerdp
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | freerdp-0:2.1.1-2.el7 | Fixed | RHSA-2020:4031 |
| Red Hat Enterprise Linux 8 | freerdp-2:2.1.1-1.el8 | Fixed | RHSA-2020:4647 |
| Red Hat Enterprise Linux 8 | vinagre-0:3.22.0-23.el8 | Fixed | RHSA-2020:4647 |
| Red Hat Enterprise Linux 6 | freerdp | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (13)
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00080.html vendor-advisoryThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2020-13396 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1841189 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-5653 Advisory
- https://github.com/FreeRDP/FreeRDP/commit/48361c411e50826cb602c7aab773a8a20e1da6bc PatchThird Party Advisory
- https://github.com/FreeRDP/FreeRDP/commit/8fb6336a4072abcee8ce5bd6ae91104628c7bb69 Third Party Advisory
- https://github.com/FreeRDP/FreeRDP/compare/2.1.0...2.1.1 Release NotesThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/08/msg00054.html mailing-listThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/10/msg00008.html mailing-listMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-13396
- https://usn.ubuntu.com/4379-1/ vendor-advisoryThird Party Advisory
- https://usn.ubuntu.com/4382-1/ vendor-advisoryThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-13396
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published May 22, 2020
Updated Aug 4, 2024
Reserved May 22, 2020
Link CVE-2020-13396
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2020-5653 Assigner mitre
Published May 22, 2020
Updated Aug 4, 2024
Exploited since n/a
Link EUVD-2020-5653