Information disclosure in FreeRDP - CVE-2018-1000852

 

Information disclosure in FreeRDP - CVE-2018-1000852

Published: January 29, 2019


Vulnerability identifier: #VU17250
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-1000852
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to an error in channels/drdynvc/client/drdynvc_main.c, drdynvc_process_capability_request. A remote attacker can connect the rdp server with echo option and gain unauthorized access to sensitive information on the system.


Affected software

FreeRDP
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Opensuse
Fedora
remmina
pidgin-sipe
freerdp
gnome-boxes

How to mitigate CVE-2018-1000852

Install updates from vendor's website.

remmina - addressed in versions 1.3.3-1.fc28, 1.3.3-1.fc29
pidgin-sipe - addressed in versions 1.24.0-3.fc28, 1.24.0-3.fc29
freerdp - addressed in versions 2.0.0-48.20190228gitce386c8.fc29, 2.0.0-49.20190304git435872b.fc28
gnome-boxes - addressed in versions 3.28.5-2.fc28, 3.30.3-2.fc29

External References

Related Security Bulletins