VulnerabilityModified
CVE-2020-4033
In FreeRDP before version 2.1.2, there is an out of bounds read in RLEDECOMPRESS.
MEDIUM 6.5EPSS 1.84%
Does this matter?
Lower severity and a low EPSS score (1.84%). Track it; it rarely justifies an emergency change on its own.
Description
In FreeRDP before version 2.1.2, there is an out of bounds read in RLEDECOMPRESS. All FreeRDP based clients with sessions with color depth < 32 are affected. This is fixed in version 2.1.2.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
- EPSS
- 1.84% probability · 78th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-125
- Affected
- freerdp/freerdp · fedoraproject/fedora · opensuse/leap · canonical/ubuntu linux · debian/debian linux
- Source
- security-advisories@github.com
References
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00080.htmlMailing List, Third Party Advisory
- http://www.freerdp.com/2020/06/22/2_1_2-releasedRelease Notes, Vendor Advisory
- https://github.com/FreeRDP/FreeRDP/commit/0a98c450c58ec150e44781c89aa6f8e7e0f571f5Patch, Third Party Advisory
- https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-7rhj-856w-82p8Mitigation, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/10/msg00008.htmlMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6Y35HBHG2INICLSGCIKNAR7GCXEHQACQ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XOZLH35OJWIQLM7FYDXAP2EAUBDXE76V/
- https://usn.ubuntu.com/4481-1/Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00080.htmlMailing List, Third Party Advisory
- http://www.freerdp.com/2020/06/22/2_1_2-releasedRelease Notes, Vendor Advisory
- https://github.com/FreeRDP/FreeRDP/commit/0a98c450c58ec150e44781c89aa6f8e7e0f571f5Patch, Third Party Advisory
- https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-7rhj-856w-82p8Mitigation, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/10/msg00008.htmlMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6Y35HBHG2INICLSGCIKNAR7GCXEHQACQ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XOZLH35OJWIQLM7FYDXAP2EAUBDXE76V/
- https://usn.ubuntu.com/4481-1/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.