ZeroHour

CVE-2018-8786

PoC
CVSS 3.1
9.8 critical
EPSS
8%p95
Published
()
Modified
Description

FreeRDP prior to version 2.0.0-rc4 contains an Integer Truncation that leads to a Heap-Based Buffer Overflow in function update_read_bitmap_update() and results in a memory corruption and probably even a remote code execution.

Vendors
freerdpcanonicaldebianfedoraprojectredhat
Products
freerdp, ubuntu linux, debian linux, fedora, enterprise linux desktop, enterprise linux server, enterprise linux server aus, enterprise linux server eus, enterprise linux server tus, enterprise linux workstation
Weakness
CWE-680, CWE-681, CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.