Improper Certificate Validation in FreeRDP and Debian Linux - CVE-2017-2836
Published: April 24, 2018 / Updated: August 8, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
An exploitable denial of service vulnerability exists within the reading of proprietary server certificates in FreeRDP 2.0.0-beta1+android11. A specially crafted challenge packet can cause the program termination leading to a denial of service condition. An attacker can compromise the server or use man in the middle to trigger this vulnerability.
Affected software
Debian Linux
Fedora
Opensuse
remmina
freerdp
How to mitigate CVE-2017-2836
freerdp - addressed in versions 2.0.0-31.20170724gitf8c9f43.fc25, 2.0.0-31.20170724gitf8c9f43.fc26