Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2020-15103
Description:In FreeRDP less than or equal to 2.1.2, an integer overflow exists due to missing input sanitation in rdpegfx channel. All FreeRDP clients are affected. The input rectangles from the server are not checked against local surface coordinates and blindly accepted. A malicious server can send data that will crash the client later on (invalid length arguments to a `memcpy`) This has been fixed in 2.2.0. As a workaround, stop using command line arguments /gfx, /gfx-h264 and /network:auto
Test IDs: 1.3.6.1.4.1.25623.1.0.113735   1.3.6.1.4.1.25623.1.0.853406  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2020-15103
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-4r38-6hq7-j3j9
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6Y35HBHG2INICLSGCIKNAR7GCXEHQACQ/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XOZLH35OJWIQLM7FYDXAP2EAUBDXE76V/
https://github.com/FreeRDP/FreeRDP/blob/616af2d5b86dc24c7b3e89870dbcffd841d9a535/ChangeLog#L4
https://github.com/FreeRDP/FreeRDP/blob/616af2d5b86dc24c7b3e89870dbcffd841d9a535/ChangeLog#L4
https://github.com/FreeRDP/FreeRDP/pull/6382
https://github.com/FreeRDP/FreeRDP/pull/6382
https://lists.debian.org/debian-lts-announce/2023/10/msg00008.html
SuSE Security Announcement: openSUSE-SU-2020:1332 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00010.html
https://usn.ubuntu.com/4481-1/




© 1998-2025 E-Soft Inc. All rights reserved.