Integer casting vulnerability in `update_recv_secondary_order` in FreeRDP
Published Jun 22, 2020
5.3
MEDIUMCVSS 3.1
EPSS 1.84%
Description
In FreeRDP before version 2.1.2, there is an integer casting vulnerability in update_recv_secondary_order. All clients with +glyph-cache /relax-order-checks are affected. This is fixed in version 2.1.2.
Affected products
-
- Version < 2.1.2StatusaffectedConstraints-
- Version
Configuration 2
- 31
- 32
- 15.1
Configuration 3
- 18.04
- 20.04
Configuration 4
- 10.0
No data.
Red Hat Enterprise Linux 6
freerdp
Not affected
Red Hat Enterprise Linux 7
freerdp
Not affected
Red Hat Enterprise Linux 8
freerdp
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | freerdp | Not affected | n/a |
| Red Hat Enterprise Linux 7 | freerdp | Not affected | n/a |
| Red Hat Enterprise Linux 8 | freerdp | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This flaw does not affect versions of freerdp as shipped with any version of Red Hat Enterprise Linux as the vulnerable code was introduced in a newer version of freerdp.
Red Hat mitigation
Do not run the freerdp client with the +glyph-cache and /relax-order-checks options.
References (12)
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00080.html vendor-advisoryThird Party Advisory
- http://www.freerdp.com/2020/06/22/2_1_2-released Release NotesVendor Advisory
- https://access.redhat.com/security/cve/CVE-2020-4032 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1854871 Issue Tracking
- https://github.com/FreeRDP/FreeRDP/commit/e7bffa64ef5ed70bac94f823e2b95262642f5296 PatchThird Party Advisory
- https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-3898-mc89-x2vc MitigationThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/10/msg00008.html mailing-listMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6Y35HBHG2INICLSGCIKNAR7GCXEHQACQ/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XOZLH35OJWIQLM7FYDXAP2EAUBDXE76V/ vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-4032
- https://usn.ubuntu.com/4481-1/ vendor-advisoryThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-4032
Change history (0)
No recorded changes yet.