In FreeRDP after 1.0 and before 2.0.0, there is a stream out-of-bounds seek in updatereadsynchronize that could lead to a later out-of-bounds read.
[
{
"signature_version": "v1",
"target": {
"file": "libfreerdp/core/update.c"
},
"source": "https://github.com/freerdp/freerdp/commit/ed53cd148f43cbab905eaa0f5308c2bf3c48cc37",
"digest": {
"line_hashes": [
"13042919185167534114805622393490891419",
"241953358141075650034132261005884757490",
"34074634668290205622398495896884120649",
"204398317245810280528487698517683644969",
"208674663881271297301380033824081893010",
"64476915098489187241963133031093818481",
"61011359946805812857078709867111121053",
"303452396618302115624729449813086304773",
"45920698666313333821827682176108508955",
"41629547567457153198214237741416975155",
"333094466083646783385992418232216203030"
],
"threshold": 0.9
},
"deprecated": false,
"id": "CVE-2020-11046-0dce6f6a",
"signature_type": "Line"
},
{
"signature_version": "v1",
"target": {
"function": "update_read_synchronize",
"file": "libfreerdp/core/update.c"
},
"source": "https://github.com/freerdp/freerdp/commit/ed53cd148f43cbab905eaa0f5308c2bf3c48cc37",
"digest": {
"length": 101.0,
"function_hash": "131171540022544086868424748921147831000"
},
"deprecated": false,
"id": "CVE-2020-11046-13d262e7",
"signature_type": "Function"
},
{
"signature_version": "v1",
"target": {
"function": "update_recv",
"file": "libfreerdp/core/update.c"
},
"source": "https://github.com/freerdp/freerdp/commit/ed53cd148f43cbab905eaa0f5308c2bf3c48cc37",
"digest": {
"length": 1341.0,
"function_hash": "313059406748321325679007879021831652814"
},
"deprecated": false,
"id": "CVE-2020-11046-743fee68",
"signature_type": "Function"
}
]