Out-of-bounds read in rdesktop - CVE-2018-20174
Published: March 17, 2019 / Updated: May 18, 2020
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary error in the function ui_clip_handle_data(). A remote attacker can send a specially crafted request to the affected application, trigger out-of-bounds read error and read contents of memory on the system.
Affected software
Arch Linux
Gentoo Linux
SUSE Linux
Opensuse
Fedora
rdesktop (Alpine package)
rdesktop
How to mitigate CVE-2018-20174
rdesktop (Alpine package) - update to 1.8.6-r0
rdesktop - addressed in versions 1.8.4-2.fc28, 1.8.4-2.fc29