MGASA-2019-0012

Source
https://advisories.mageia.org/MGASA-2019-0012.html
Import Source
https://advisories.mageia.org/MGASA-2019-0012.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2019-0012
Related
Published
2019-01-05T18:30:16Z
Modified
2019-01-05T18:04:04Z
Summary
Updated freerdp packages fix security vulnerabilities
Details

Eyal Itkin discovered FreeRDP incorrectly handled certain stream encodings. A malicious server could use this issue to cause FreeRDP to crash, resulting in a denial of service, or possibly execute arbitrary code (CVE-2018-8784, CVE-2018-8785).

Eyal Itkin discovered FreeRDP incorrectly handled bitmaps. A malicious server could use this issue to cause FreeRDP to crash, resulting in a denial of service, or possibly execute arbitrary code (CVE-2018-8786, CVE-2018-8787).

Eyal Itkin discovered FreeRDP incorrectly handled certain stream encodings. A malicious server could use this issue to cause FreeRDP to crash, resulting in a denial of service, or possibly execute arbitrary code (CVE-2018-8788).

Eyal Itkin discovered FreeRDP incorrectly handled NTLM authentication. A malicious server could use this issue to cause FreeRDP to crash, resulting in a denial of service, or possibly execute arbitrary code (CVE-2018-8789).

References
Credits

Affected packages