Input validation error in FreeRDP and Debian Linux - CVE-2017-2838
Published: April 24, 2018 / Updated: August 8, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
An exploitable denial of service vulnerability exists within the handling of challenge packets in FreeRDP 2.0.0-beta1+android11. A specially crafted challenge packet can cause the program termination leading to a denial of service condition. An attacker can compromise the server or use man in the middle to trigger this vulnerability.
Affected software
Debian Linux
Fedora
Opensuse
remmina
freerdp
How to mitigate CVE-2017-2838
freerdp - addressed in versions 2.0.0-31.20170724gitf8c9f43.fc25, 2.0.0-31.20170724gitf8c9f43.fc26