Out-of-bounds read in Debian Linux - CVE-2018-20178
Published: March 15, 2019 / Updated: August 4, 2020
Vulnerability identifier: #VU33451
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-20178
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in the function process_demand_active() that results in a Denial of Service (segfault).
Affected software
Debian Linux
Arch Linux
Gentoo Linux
SUSE Linux
Opensuse
Fedora
rdesktop (Alpine package)
rdesktop
Arch Linux
Gentoo Linux
SUSE Linux
Opensuse
Fedora
rdesktop (Alpine package)
rdesktop
How to mitigate CVE-2018-20178
Install update from vendor's website.
rdesktop (Alpine package) - update to 1.8.6-r0
rdesktop - addressed in versions 1.8.4-2.fc28, 1.8.4-2.fc29
rdesktop - addressed in versions 1.8.4-2.fc28, 1.8.4-2.fc29
Links to Public Exploits and PoC-codes
External References
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00040.html
- http://www.securityfocus.com/bid/106938
- https://github.com/rdesktop/rdesktop/commit/4dca546d04321a610c1835010b5dad85163b65e1
- https://lists.debian.org/debian-lts-announce/2019/02/msg00030.html
- https://research.checkpoint.com/reverse-rdp-attack-code-execution-on-rdp-clients/
- https://security.gentoo.org/glsa/201903-06
- https://www.debian.org/security/2019/dsa-4394