ZeroHour

CVE-2020-11039

CVSS 3.1
6.8 medium
EPSS
1%p68
Published
()
Modified
Description

In FreeRDP less than or equal to 2.0.0, when using a manipulated server with USB redirection enabled (nearly) arbitrary memory can be read and written due to integer overflows in length checks. This has been patched in 2.1.0.

Vendors
freerdpopensusedebian
Products
freerdp, leap, debian linux
Weakness
CWE-190
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:L

In the news

No ingested article mentions this CVE yet.