ZeroHour

CVE-2018-8787

PoC
CVSS 3.1
9.8 critical
EPSS
8%p95
Published
()
Modified
Description

FreeRDP prior to version 2.0.0-rc4 contains an Integer Overflow that leads to a Heap-Based Buffer Overflow in function gdi_Bitmap_Decompress() and results in a memory corruption and probably even a remote code execution.

Vendors
freerdpcanonicaldebianredhat
Products
freerdp, ubuntu linux, debian linux, enterprise linux desktop, enterprise linux eus, enterprise linux server, enterprise linux server aus, enterprise linux server tus, enterprise linux workstation
Weakness
CWE-680, CWE-190, CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.