In FreeRDP after 1.0 and before 2.0.0, there is an out-of-bound read in in updatereadbitmap_data that allows client memory to be read to an image buffer. The result displayed on screen as colour.
[
{
"id": "CVE-2020-11045-28b89200",
"deprecated": false,
"digest": {
"length": 1297.0,
"function_hash": "206436341201980652058609057959198552998"
},
"target": {
"file": "libfreerdp/core/update.c",
"function": "update_read_bitmap_data"
},
"source": "https://github.com/freerdp/freerdp/commit/f8890a645c221823ac133dbf991f8a65ae50d637",
"signature_type": "Function",
"signature_version": "v1"
},
{
"id": "CVE-2020-11045-8488ed58",
"deprecated": false,
"digest": {
"line_hashes": [
"174082662618401205352853601715769749832",
"84560628654313816427147087026633431051",
"182426011417203487958277892954071378642",
"308865737782997131972517872718766365445"
],
"threshold": 0.9
},
"target": {
"file": "libfreerdp/core/update.c"
},
"source": "https://github.com/freerdp/freerdp/commit/f8890a645c221823ac133dbf991f8a65ae50d637",
"signature_type": "Line",
"signature_version": "v1"
}
]