FreeRDP is a client implementation of the Remote Desktop Protocol (RDP) that follows Microsoft's open specifications. This package provides the client applications xfreerdp and wlfreerdp.\r\n\r\n Security Fix(es):\r\n\r\n libfreerdp/core/update.c in FreeRDP versions > 1.1 through 2.0.0-rc4 has an Out-of-bounds Read.(CVE-2020-11526)\r\n\r\n In FreeRDP greater than 1.2 and before 2.0.0, a double free in updatereadcachebitmapv3order crashes the client application if corrupted data from a manipulated server is parsed. This has been patched in 2.0.0.(CVE-2020-11044)\r\n\r\n In FreeRDP greater than 1.1 and before 2.0.0, there is an out-of-bounds read in updatereadiconinfo. It allows reading a attacker-defined amount of client memory (32bit unsigned -> 4GB) to an intermediate buffer. This can be used to crash the client or store information for later retrieval. This has been patched in 2.0.0.(CVE-2020-11042)\r\n\r\n In FreeRDP before version 2.1.2, an out of bound reads occurs resulting in accessing a memory location that is outside of the boundaries of the static array PRIMARYDRAWINGORDERFIELDBYTES. This is fixed in version 2.1.2.(CVE-2020-11095)\r\n\r\n In FreeRDP after 1.0 and before 2.0.0, there is an out-of-bound read in in updatereadbitmap_data that allows client memory to be read to an image buffer. The result displayed on screen as colour.(CVE-2020-11045)\r\n\r\n libfreerdp/gdi/gdi.c in FreeRDP > 1.0 through 2.0.0-rc4 has an Out-of-bounds Read.(CVE-2020-11522)\r\n\r\n libfreerdp/codec/interleaved.c in FreeRDP versions > 1.0 through 2.0.0-rc4 has an Out-of-bounds Write.(CVE-2020-11524)\r\n\r\n libfreerdp/codec/planar.c in FreeRDP version > 1.0 through 2.0.0-rc4 has an Out-of-bounds Write.(CVE-2020-11521)\r\n\r\n libfreerdp/cache/bitmap.c in FreeRDP versions > 1.0 through 2.0.0-rc4 has an Out of bounds read.(CVE-2020-11525)\r\n\r\n libfreerdp/codec/planar.c in FreeRDP version > 1.0 through 2.0.0-rc4 has an Out-of-bounds Write.(CVE-2020-11521)\r\n\r\n libfreerdp/codec/region.c in FreeRDP through 1.1.x and 2.x through 2.0.0-rc4 has memory leaks because a supplied realloc pointer (i.e., the first argument to realloc) is also used for a realloc return value.(CVE-2019-17177)\r\n\r\n
{ "severity": "Medium" }
{ "aarch64": [ "freerdp-debugsource-2.2.0-2.oe1.aarch64.rpm", "libwinpr-2.2.0-2.oe1.aarch64.rpm", "freerdp-help-2.2.0-2.oe1.aarch64.rpm", "freerdp-debuginfo-2.2.0-2.oe1.aarch64.rpm", "libwinpr-devel-2.2.0-2.oe1.aarch64.rpm", "freerdp-2.2.0-2.oe1.aarch64.rpm", "freerdp-devel-2.2.0-2.oe1.aarch64.rpm", "freerdp-debugsource-2.2.0-2.oe1.aarch64.rpm", "libwinpr-2.2.0-2.oe1.aarch64.rpm", "freerdp-help-2.2.0-2.oe1.aarch64.rpm", "freerdp-debuginfo-2.2.0-2.oe1.aarch64.rpm", "libwinpr-devel-2.2.0-2.oe1.aarch64.rpm", "freerdp-2.2.0-2.oe1.aarch64.rpm", "freerdp-devel-2.2.0-2.oe1.aarch64.rpm" ], "src": [ "freerdp-2.2.0-2.oe1.src.rpm", "freerdp-2.2.0-2.oe1.src.rpm" ], "x86_64": [ "libwinpr-2.2.0-2.oe1.x86_64.rpm", "libwinpr-devel-2.2.0-2.oe1.x86_64.rpm", "freerdp-devel-2.2.0-2.oe1.x86_64.rpm", "freerdp-help-2.2.0-2.oe1.x86_64.rpm", "freerdp-debuginfo-2.2.0-2.oe1.x86_64.rpm", "freerdp-2.2.0-2.oe1.x86_64.rpm", "freerdp-debugsource-2.2.0-2.oe1.x86_64.rpm", "libwinpr-2.2.0-2.oe1.x86_64.rpm", "libwinpr-devel-2.2.0-2.oe1.x86_64.rpm", "freerdp-devel-2.2.0-2.oe1.x86_64.rpm", "freerdp-help-2.2.0-2.oe1.x86_64.rpm", "freerdp-debuginfo-2.2.0-2.oe1.x86_64.rpm", "freerdp-2.2.0-2.oe1.x86_64.rpm", "freerdp-debugsource-2.2.0-2.oe1.x86_64.rpm" ] }
{ "aarch64": [ "freerdp-debugsource-2.2.0-2.oe1.aarch64.rpm", "libwinpr-2.2.0-2.oe1.aarch64.rpm", "freerdp-help-2.2.0-2.oe1.aarch64.rpm", "freerdp-debuginfo-2.2.0-2.oe1.aarch64.rpm", "libwinpr-devel-2.2.0-2.oe1.aarch64.rpm", "freerdp-2.2.0-2.oe1.aarch64.rpm", "freerdp-devel-2.2.0-2.oe1.aarch64.rpm" ], "src": [ "freerdp-2.2.0-2.oe1.src.rpm" ], "x86_64": [ "libwinpr-2.2.0-2.oe1.x86_64.rpm", "libwinpr-devel-2.2.0-2.oe1.x86_64.rpm", "freerdp-devel-2.2.0-2.oe1.x86_64.rpm", "freerdp-help-2.2.0-2.oe1.x86_64.rpm", "freerdp-debuginfo-2.2.0-2.oe1.x86_64.rpm", "freerdp-2.2.0-2.oe1.x86_64.rpm", "freerdp-debugsource-2.2.0-2.oe1.x86_64.rpm" ] }