Back

HIGH

Use-After-Free in gdi_SelectObject in FreeRDP

Published Jun 22, 2020

Description

In FreeRDP before version 2.1.2, there is a use-after-free in gdi_SelectObject. All FreeRDP clients using compatibility mode with /relax-order-checks are affected. This is fixed in version 2.1.2.

Affected products

Remediation

Red Hat statement

Although the vulnerable code could have been in versions of freerdp shipped with Red Hat Enterprise Linux 7 and 8, the build configuration disables the shadow-server functionality and thus the vulnerable code is not shipped. Therefore, versions of freerdp shipped with Red Hat Enterprise Linux 7 and 8 are not affected. The version of freerdp shipped with Red Hat Enterprise Linux 6 does not contain the vulnerable code in the first place.

Weaknesses (1)

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Jun 22, 2020
Updated Aug 4, 2024
Reserved Dec 30, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jun 22, 2020
ENISA EUVD
Assigner GitHub_M
Published Jun 22, 2020
Updated Aug 4, 2024
Exploited since n/a
EUVD-2020-25296