Integer overflow - CVE-2018-20177
Published: March 15, 2019 / Updated: August 4, 2020
Vulnerability identifier: #VU33450
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-20177
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to integer overflow in function rdp_in_unistr(). A remote attacker can send a crafted request to the affected application, trigger memory corruption and possibly even a remote code execution.
Affected software
Arch Linux
Gentoo Linux
SUSE Linux
Opensuse
Fedora
rdesktop (Alpine package)
rdesktop
Gentoo Linux
SUSE Linux
Opensuse
Fedora
rdesktop (Alpine package)
rdesktop
How to mitigate CVE-2018-20177
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.
rdesktop (Alpine package) - update to 1.8.6-r0
rdesktop - addressed in versions 1.8.4-2.fc28, 1.8.4-2.fc29
rdesktop - addressed in versions 1.8.4-2.fc28, 1.8.4-2.fc29
Links to Public Exploits and PoC-codes
External References
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00040.html
- http://www.securityfocus.com/bid/106938
- https://github.com/rdesktop/rdesktop/commit/4dca546d04321a610c1835010b5dad85163b65e1
- https://lists.debian.org/debian-lts-announce/2019/02/msg00030.html
- https://research.checkpoint.com/reverse-rdp-attack-code-execution-on-rdp-clients/
- https://security.gentoo.org/glsa/201903-06
- https://www.debian.org/security/2019/dsa-4394