Candidate: CVE-2020-11085 PublicDate: 2020-05-29 20:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11085 https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-2j4w-v45m-95hf Description: In FreeRDP before 2.1.0, there is an out-of-bounds read in cliprdr_read_format_list. Clipboard format data read (by client or server) might read data out-of-bounds. This has been fixed in 2.1.0. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L [3.5 LOW] Patches_freerdp2: upstream: https://github.com/FreeRDP/FreeRDP/commit/b73143cf7ee5fe4cdabcbf56908aa15d8a883821 upstream_freerdp2: released (2.1.1+dfsg1-1) precise/esm_freerdp2: DNE trusty_freerdp2: ignored (out of standard support) trusty/esm_freerdp2: DNE xenial_freerdp2: DNE bionic_freerdp2: released (2.1.1+dfsg1-0ubuntu0.18.04.1) eoan_freerdp2: released (2.1.1+dfsg1-0ubuntu0.19.10.1) focal_freerdp2: released (2.1.1+dfsg1-0ubuntu0.20.04.1) devel_freerdp2: not-affected (2.1.1+dfsg1-1) Patches_freerdp: upstream_freerdp: needs-triage precise/esm_freerdp: DNE trusty_freerdp: ignored (out of standard support) trusty/esm_freerdp: DNE xenial_freerdp: not-affected (code not present) esm-infra/xenial_freerdp: not-affected (code not present) bionic_freerdp: not-affected (code not present) eoan_freerdp: DNE focal_freerdp: DNE devel_freerdp: DNE