MEDIUM
freerdp: Out-of-bounds read in security_fips_decrypt in libfreerdp/core/security.c
Published May 22, 2020
6.1
MEDIUMCVSS 3.1
EPSS 0.54%
Description
An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) read vulnerability has been detected in security_fips_decrypt in libfreerdp/core/security.c due to an uninitialized value.
Affected products
No data.
Configuration 2
OR
- 16.04
- 18.04
- 19.10
- 20.04
- 9.0
- 10.0
- 15.1
No data.
Red Hat Enterprise Linux 7
freerdp-0:2.1.1-2.el7
Fixed · RHSA-2020:4031
Red Hat Enterprise Linux 8
freerdp-2:2.1.1-1.el8
Fixed · RHSA-2020:4647
Red Hat Enterprise Linux 8
vinagre-0:3.22.0-23.el8
Fixed · RHSA-2020:4647
Red Hat Enterprise Linux 6
freerdp
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | freerdp-0:2.1.1-2.el7 | Fixed | RHSA-2020:4031 |
| Red Hat Enterprise Linux 8 | freerdp-2:2.1.1-1.el8 | Fixed | RHSA-2020:4647 |
| Red Hat Enterprise Linux 8 | vinagre-0:3.22.0-23.el8 | Fixed | RHSA-2020:4647 |
| Red Hat Enterprise Linux 6 | freerdp | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (12)
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00080.html vendor-advisoryThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2020-13397 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1841196 Issue Tracking
- https://github.com/FreeRDP/FreeRDP/commit/8fb6336a4072abcee8ce5bd6ae91104628c7bb69 Third Party Advisory
- https://github.com/FreeRDP/FreeRDP/commit/d6cd14059b257318f176c0ba3ee0a348826a9ef8 PatchThird Party Advisory
- https://github.com/FreeRDP/FreeRDP/compare/2.1.0...2.1.1 Release NotesThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/08/msg00054.html mailing-listThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/10/msg00008.html mailing-listMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-13397
- https://usn.ubuntu.com/4379-1/ vendor-advisoryThird Party Advisory
- https://usn.ubuntu.com/4382-1/ vendor-advisoryThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-13397
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published May 22, 2020
Updated Aug 4, 2024
Reserved May 22, 2020
Link CVE-2020-13397
CISA Vulnrichment
Updated n/a