Out-of-bounds read in FreeRDP - CVE-2018-8789
Published: December 18, 2018
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition.
The vulnerability exists due to several out-of-bound read conditions that exist in the NTLM authentication module. A remote attacker can send a specially crafted request that submits malicious input, trigger several out-of-bounds read conditions that the attacker can use to cause a DoS condition.
Affected software
freerdp (Ubuntu package)
freerdp (Alpine package)
Opensuse
How to mitigate CVE-2018-8789
freerdp (Ubuntu package) - addressed in versions 1.1.0~git20140921.1.440916e+dfsg1-15ubuntu1.18.04.1, 1.1.0~git20140921.1.440916e+dfsg1-15ubuntu1.18.10.1
freerdp (Alpine package) - update to 2.0.0_rc4-r0