Input validation error in FreeRDP and Debian Linux - CVE-2017-2839

 

Input validation error in FreeRDP and Debian Linux - CVE-2017-2839

Published: April 24, 2018 / Updated: August 8, 2020


Vulnerability identifier: #VU37168
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-2839
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.

An exploitable denial of service vulnerability exists within the handling of challenge packets in FreeRDP 2.0.0-beta1+android11. A specially crafted challenge packet can cause the program termination leading to a denial of service condition. An attacker can compromise the server or use man in the middle to trigger this vulnerability.


Affected software

FreeRDP
Debian Linux
Fedora
Opensuse
remmina
freerdp

How to mitigate CVE-2017-2839

Install update from vendor's website.

remmina - addressed in versions 1.2.0-0.39.20170724git0387ee0.fc25, 1.2.0-0.39.20170724git0387ee0.fc26
freerdp - addressed in versions 2.0.0-31.20170724gitf8c9f43.fc25, 2.0.0-31.20170724gitf8c9f43.fc26

External References

Related Security Bulletins