SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-4030

Logging might bypass string length checks due to an integer overflow.

MEDIUM 6.5EPSS 1.85%

Does this matter?

Lower severity and a low EPSS score (1.85%). Track it; it rarely justifies an emergency change on its own.

Description

In FreeRDP before version 2.1.2, there is an out of bounds read in TrioParse. Logging might bypass string length checks due to an integer overflow. This is fixed in version 2.1.2.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
EPSS
1.85% probability · 78th percentile
CISA KEV
Not listed
Weakness
CWE-125, CWE-190
Affected
freerdp/freerdp · fedoraproject/fedora · opensuse/leap · canonical/ubuntu linux · debian/debian linux
Source
security-advisories@github.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.