Heap-based buffer overflow in FreeRDP - CVE-2018-8786
Published: December 18, 2018 / Updated: May 18, 2020
Vulnerability details
The vulnerability allows a remote authenticated attacker to cause DoS condition or execute arbitrary code.
The vulnerability exists due to improper handling of bitmaps by the update_read_bitmap_update() function, as defined in the update.c source code file. A remote attacker can send a specially crafted request that submits malicious input, trigger a heap-based buffer overflow condition that the attacker can use to cause a DoS condition or execute arbitrary code with elevated privileges.
Successful exploitation of the vulnerability may result in system compromise.
Affected software
freerdp (Ubuntu package)
freerdp (Alpine package)
remmina
pidgin-sipe
freerdp
gnome-boxes
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power
Opensuse
Fedora
How to mitigate CVE-2018-8786
freerdp (Ubuntu package) - addressed in versions 1.1.0~git20140921.1.440916e+dfsg1-15ubuntu1.18.04.1, 1.1.0~git20140921.1.440916e+dfsg1-15ubuntu1.18.10.1
freerdp (Alpine package) - addressed in versions 2.0.0_rc4-r0, 2.0.0-r0
remmina - addressed in versions 1.3.3-1.fc28, 1.3.3-1.fc29
pidgin-sipe - addressed in versions 1.24.0-3.fc28, 1.24.0-3.fc29
freerdp - addressed in versions 2.0.0-48.20190228gitce386c8.fc29, 2.0.0-49.20190304git435872b.fc28
gnome-boxes - addressed in versions 3.28.5-2.fc28, 3.30.3-2.fc29
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Multiple vulnerabilities in FreeRDP
- OpenSUSE Linux update for freerdp
- OpenSUSE Linux update for freerdp
- Ubuntu update for FreeRDP
- Red Hat update for freerdp
- Heap-based buffer overflow in freerdp (Alpine package)
- Fedora 29 update for freerdp, gnome-boxes, pidgin-sipe, remmina
- Fedora 28 update for freerdp, gnome-boxes, pidgin-sipe, remmina