RLSA-2020:4647

Source
https://errata.rockylinux.org/RLSA-2020:4647
Import Source
https://storage.googleapis.com/resf-osv-data/RLSA-2020:4647.json
JSON Data
https://api.test.osv.dev/v1/vulns/RLSA-2020:4647
Related
Published
2020-11-03T12:23:37Z
Modified
2023-02-02T13:08:28.394085Z
Severity
  • 7.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L CVSS Calculator
Summary
Moderate: freerdp and vinagre security, bug fix, and enhancement update
Details

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. The xfreerdp client can connect to RDP servers such as Microsoft Windows machines, xrdp, and VirtualBox.

The vinagre packages provide the Vinagre remote desktop viewer for the GNOME desktop.

The following packages have been upgraded to a later upstream version: freerdp (2.1.1). (BZ#1834287)

Security Fix(es):

  • freerdp: Out of bound read in cliprdrserverreceive_capabilities (CVE-2020-11018)

  • freerdp: Out of bound read/write in usb redirection channel (CVE-2020-11039)

  • freerdp: out-of-bounds read in updatereadicon_info function (CVE-2020-11042)

  • freerdp: out-of-bounds read in autodetectrecvbandwidthmeasureresults function (CVE-2020-11047)

  • freerdp: Out-of-bounds read in ntlmreadChallengeMessage in winpr/libwinpr/sspi/NTLM/ntlm_message.c. (CVE-2020-13396)

  • freerdp: Out-of-bounds read in securityfipsdecrypt in libfreerdp/core/security.c (CVE-2020-13397)

  • freerdp: Out of bound read in update_recv could result in a crash (CVE-2020-11019)

  • freerdp: Integer overflow in VIDEO channel (CVE-2020-11038)

  • freerdp: Out of bound access in cleardecompresssubcode_rlex (CVE-2020-11040)

  • freerdp: Unchecked read of array offset in rdpsndrecvwave2_pdu (CVE-2020-11041)

  • freerdp: out of bound read in rfxprocessmessage_tileset (CVE-2020-11043)

  • freerdp: double free in updatereadcachebitmapv3_order function (CVE-2020-11044)

  • freerdp: out of bounds read in updatereadbitmap_data function (CVE-2020-11045)

  • freerdp: out of bounds seek in updatereadsynchronize function could lead out of bounds read (CVE-2020-11046)

  • freerdp: out-of-bounds read could result in aborting the session (CVE-2020-11048)

  • freerdp: out-of-bound read of client memory that is then passed on to the protocol parser (CVE-2020-11049)

  • freerdp: stream out-of-bounds seek in rdpreadfontcapabilityset could lead to out-of-bounds read (CVE-2020-11058)

  • freerdp: out-of-bounds read in cliprdrreadformat_list function (CVE-2020-11085)

  • freerdp: out-of-bounds read in ntlmreadntlmv2client_challenge function (CVE-2020-11086)

  • freerdp: out-of-bounds read in ntlmreadAuthenticateMessage (CVE-2020-11087)

  • freerdp: out-of-bounds read in ntlmreadNegotiateMessage (CVE-2020-11088)

  • freerdp: out-of-bounds read in irp functions (CVE-2020-11089)

  • freerdp: out-of-bounds read in gdi.c (CVE-2020-11522)

  • freerdp: out-of-bounds read in bitmap.c (CVE-2020-11525)

  • freerdp: Stream pointer out of bounds in updaterecvsecondary_order could lead out of bounds read later (CVE-2020-11526)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Rocky Linux 8.3 Release Notes linked from the References section.

References
Credits
    • Rocky Enterprise Software Foundation
    • Red Hat

Affected packages

Rocky Linux:8 / vinagre

Package

Name
vinagre
Purl
pkg:rpm/rocky-linux/vinagre?distro=rocky-linux-8&epoch=0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0:3.22.0-23.el8