Candidate: CVE-2020-11089 PublicDate: 2020-05-29 20:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11089 https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-hfc7-c5gv-8c2h Description: In FreeRDP before 2.1.0, there is an out-of-bound read in irp functions (parallel_process_irp_create, serial_process_irp_create, drive_process_irp_write, printer_process_irp_write, rdpei_recv_pdu, serial_process_irp_write). This has been fixed in 2.1.0. Ubuntu-Description: Notes: mdeslaur> The freerdp package in Ubuntu 16.04 LTS and Ubuntu 18.04 LTS mdeslaur> does not build a server library. This is simply a client mdeslaur> denial of service that has a negligible security impact. Mitigation: Bugs: Priority: low Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L [5.5 MEDIUM] Patches_freerdp2: upstream: https://github.com/FreeRDP/FreeRDP/commit/6b485b146a1b9d6ce72dfd7b5f36456c166e7a16 upstream: https://github.com/FreeRDP/FreeRDP/commit/795842f4096501fcefc1a7f535ccc8132feb31d7 upstream_freerdp2: released (2.1.1+dfsg1-1) precise/esm_freerdp2: DNE trusty_freerdp2: ignored (out of standard support) trusty/esm_freerdp2: DNE xenial_freerdp2: DNE bionic_freerdp2: released (2.1.1+dfsg1-0ubuntu0.18.04.1) eoan_freerdp2: released (2.1.1+dfsg1-0ubuntu0.19.10.1) focal_freerdp2: released (2.1.1+dfsg1-0ubuntu0.20.04.1) groovy_freerdp2: not-affected (2.1.1+dfsg1-1) hirsute_freerdp2: not-affected (2.1.1+dfsg1-1) impish_freerdp2: not-affected (2.1.1+dfsg1-1) jammy_freerdp2: not-affected (2.1.1+dfsg1-1) devel_freerdp2: not-affected (2.1.1+dfsg1-1) Patches_freerdp: Priority_freerdp: negligible upstream_freerdp: needs-triage precise/esm_freerdp: DNE trusty_freerdp: ignored (out of standard support) trusty/esm_freerdp: DNE xenial_freerdp: ignored (end of standard support, was needed) esm-infra/xenial_freerdp: needed bionic_freerdp: needed eoan_freerdp: DNE focal_freerdp: DNE groovy_freerdp: DNE hirsute_freerdp: DNE impish_freerdp: DNE jammy_freerdp: DNE devel_freerdp: DNE