CVE-2018-1000852
FreeRDP FreeRDP 2.0.0-rc3 released version before commit 205c612820dac644d665b5bb1cdf437dc5ca01e3 contains a Other/Unknown vulnerability in channels/drdynvc/client/drdynvc_main.c, drdynvc_process_capability_request that can result in The RDP server can…
Does this matter?
Lower severity and a low EPSS score (2.67%). Track it; it rarely justifies an emergency change on its own.
Description
FreeRDP FreeRDP 2.0.0-rc3 released version before commit 205c612820dac644d665b5bb1cdf437dc5ca01e3 contains a Other/Unknown vulnerability in channels/drdynvc/client/drdynvc_main.c, drdynvc_process_capability_request that can result in The RDP server can read the client's memory.. This attack appear to be exploitable via RDPClient must connect the rdp server with echo option. This vulnerability appears to have been fixed in after commit 205c612820dac644d665b5bb1cdf437dc5ca01e3.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
- EPSS
- 2.67% probability · 85th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-125
- Affected
- freerdp/freerdp · canonical/ubuntu linux · fedoraproject/fedora
- Source
- cve@mitre.org
References
- https://access.redhat.com/errata/RHSA-2019:2157Third Party Advisory
- https://github.com/FreeRDP/FreeRDP/issues/4866Exploit, Third Party Advisory
- https://github.com/FreeRDP/FreeRDP/pull/4871Third Party Advisory
- https://github.com/FreeRDP/FreeRDP/pull/4871/commits/baee520e3dd9be6511c45a14c5f5e77784de1471Patch, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YVJKO2DR5EY4C4QZOP7SNNBEW2JW6FHX/
- https://usn.ubuntu.com/4379-1/Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2157Third Party Advisory
- https://github.com/FreeRDP/FreeRDP/issues/4866Exploit, Third Party Advisory
- https://github.com/FreeRDP/FreeRDP/pull/4871Third Party Advisory
- https://github.com/FreeRDP/FreeRDP/pull/4871/commits/baee520e3dd9be6511c45a14c5f5e77784de1471Patch, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YVJKO2DR5EY4C4QZOP7SNNBEW2JW6FHX/
- https://usn.ubuntu.com/4379-1/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.