MEDIUM
OOB read in `TrioParse` in FreeRDP
Published Jun 22, 2020
6.5
MEDIUMCVSS 3.1
EPSS 1.85%
Description
In FreeRDP before version 2.1.2, there is an out of bounds read in TrioParse. Logging might bypass string length checks due to an integer overflow. This is fixed in version 2.1.2.
Affected products
-
- Version < 2.1.2StatusaffectedConstraints-
- Version
Configuration 2
OR
- 31
- 32
Configuration 4
OR
- 18.04
- 20.04
Configuration 5
- 10.0
No data.
Red Hat Enterprise Linux 8
freerdp-2:2.2.0-1.el8
Fixed · RHSA-2021:1849
Red Hat Enterprise Linux 6
freerdp
Not affected
Red Hat Enterprise Linux 7
freerdp
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | freerdp-2:2.2.0-1.el8 | Fixed | RHSA-2021:1849 |
| Red Hat Enterprise Linux 6 | freerdp | Not affected | n/a |
| Red Hat Enterprise Linux 7 | freerdp | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (12)
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00080.html vendor-advisoryMailing ListThird Party Advisory
- http://www.freerdp.com/2020/06/22/2_1_2-released Release NotesVendor Advisory
- https://access.redhat.com/security/cve/CVE-2020-4030 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1854895 Issue Tracking
- https://github.com/FreeRDP/FreeRDP/commit/05cd9ea2290d23931f615c1b004d4b2e69074e27 PatchThird Party Advisory
- https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-fjr5-97f5-qq98 Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/10/msg00008.html mailing-listMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6Y35HBHG2INICLSGCIKNAR7GCXEHQACQ/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XOZLH35OJWIQLM7FYDXAP2EAUBDXE76V/ vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-4030
- https://usn.ubuntu.com/4481-1/ vendor-advisoryThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-4030
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Jun 22, 2020
Updated Aug 4, 2024
Reserved Dec 30, 2019
Link CVE-2020-4030
CISA Vulnrichment
Updated n/a