PublicDateAtUSN: 2020-05-07 20:15:00 UTC Candidate: CVE-2020-11049 PublicDate: 2020-05-07 20:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11049 https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-wwh7-r2r8-xjpr https://github.com/FreeRDP/FreeRDP/pull/6019 https://ubuntu.com/security/notices/USN-4379-1 https://ubuntu.com/security/notices/USN-4382-1 Description: In FreeRDP after 1.1 and before 2.0.0, there is an out-of-bound read of client memory that is then passed on to the protocol parser. This has been patched in 2.0.0. Ubuntu-Description: Notes: mdeslaur> included in same commit as CVE-2020-11048 Mitigation: Bugs: https://github.com/FreeRDP/FreeRDP/issues/6008 Priority: low Discovered-by: Assigned-to: mdeslaur CVSS: nvd: CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L [2.2 LOW] Patches_freerdp2: upstream: https://github.com/FreeRDP/FreeRDP/commit/c367f65d42e0d2e1ca248998175180aa9c2eacd0 upstream: https://github.com/FreeRDP/FreeRDP/commit/9301bfe730c66180263248b74353daa99f5a969b upstream_freerdp2: needs-triage precise/esm_freerdp2: DNE trusty_freerdp2: ignored (out of standard support) trusty/esm_freerdp2: DNE xenial_freerdp2: DNE bionic_freerdp2: released (2.1.1+dfsg1-0ubuntu0.18.04.1) eoan_freerdp2: released (2.1.1+dfsg1-0ubuntu0.19.10.1) focal_freerdp2: released (2.1.1+dfsg1-0ubuntu0.20.04.1) groovy_freerdp2: not-affected (2.1.1+dfsg1-1) hirsute_freerdp2: not-affected (2.1.1+dfsg1-1) impish_freerdp2: not-affected (2.1.1+dfsg1-1) jammy_freerdp2: not-affected (2.1.1+dfsg1-1) devel_freerdp2: not-affected (2.1.1+dfsg1-1) Patches_freerdp: upstream_freerdp: needs-triage precise/esm_freerdp: DNE trusty_freerdp: ignored (out of standard support) trusty/esm_freerdp: DNE xenial_freerdp: released (1.1.0~git20140921.1.440916e+dfsg1-5ubuntu1.4) esm-infra/xenial_freerdp: released (1.1.0~git20140921.1.440916e+dfsg1-5ubuntu1.4) bionic_freerdp: needs-triage eoan_freerdp: DNE focal_freerdp: DNE groovy_freerdp: DNE hirsute_freerdp: DNE impish_freerdp: DNE jammy_freerdp: DNE devel_freerdp: DNE