Out-of-bounds read in rdesktop - CVE-2018-20176
Published: March 18, 2019
Vulnerability details
The vulnerability allows a remote attacker to perform denial of service (DoS) attack.
The vulnerability exists due to a boundary condition when processing RDP packets in sec_parse_crypt_info() and sec_recv() functionsin secure.cfile. A remote attacker can trick the victim that is using the vulnerable RDP client to connect to malicious RDP server, trigger out-of-bounds read error and perform denial of service attack.
Affected software
Gentoo Linux
Arch Linux
SUSE Linux
Opensuse
Fedora
busybox (Alpine package)
rdesktop (Alpine package)
firefox-esr (Alpine package)
rdesktop
How to mitigate CVE-2018-20176
rdesktop (Alpine package) - update to 1.8.6-r0
rdesktop - addressed in versions 1.8.4-2.fc28, 1.8.4-2.fc29
External References
Related Security Bulletins
- Out-of-bounds read in rdesktop rdesktop
- OpenSUSE Linux update for rdesktop
- Out-of-bounds read in rdesktop (Alpine package)
- Out-of-bounds read in busybox (Alpine package)
- Arch Linux update for rdesktop
- Gentoo update for rdesktop
- Out-of-bounds read in firefox-esr (Alpine package)
- Fedora 28 update for rdesktop
- Fedora 29 update for rdesktop