In FreeRDP after 1.0 and before 2.0.0, there is an out-of-bound read in in updatereadbitmap_data that allows client memory to be read to an image buffer. The result displayed on screen as colour.
{ "vanir_signatures": [ { "digest": { "length": 1297.0, "function_hash": "206436341201980652058609057959198552998" }, "target": { "function": "update_read_bitmap_data", "file": "libfreerdp/core/update.c" }, "id": "CVE-2020-11045-28b89200", "signature_type": "Function", "deprecated": false, "source": "https://github.com/freerdp/freerdp/commit/f8890a645c221823ac133dbf991f8a65ae50d637", "signature_version": "v1" }, { "digest": { "line_hashes": [ "174082662618401205352853601715769749832", "84560628654313816427147087026633431051", "182426011417203487958277892954071378642", "308865737782997131972517872718766365445" ], "threshold": 0.9 }, "target": { "file": "libfreerdp/core/update.c" }, "id": "CVE-2020-11045-8488ed58", "signature_type": "Line", "deprecated": false, "source": "https://github.com/freerdp/freerdp/commit/f8890a645c221823ac133dbf991f8a65ae50d637", "signature_version": "v1" } ] }