FreeRDP prior to version 2.0.0-rc4 contains an Integer Overflow that leads to a Heap-Based Buffer Overflow in function gdiBitmapDecompress() and results in a memory corruption and probably even a remote code execution.
[
{
"source": "https://github.com/freerdp/freerdp/commit/09b9d4f1994a674c4ec85b4947aa656eda1aed8a",
"target": {
"file": "libfreerdp/gdi/graphics.c"
},
"deprecated": false,
"signature_version": "v1",
"id": "CVE-2018-8787-541c12ca",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"142865726376982088631373613877219078405",
"236894524919394771385228552050113126284",
"156281514602602350502823222766545680591",
"93900013262784643692160102310424641575",
"138071301120981546982753408783923712123",
"128875901202263930011326215047824072228",
"214661022474973991757884160097779462986"
]
}
},
{
"source": "https://github.com/freerdp/freerdp/commit/09b9d4f1994a674c4ec85b4947aa656eda1aed8a",
"target": {
"function": "gdi_Bitmap_Decompress",
"file": "libfreerdp/gdi/graphics.c"
},
"deprecated": false,
"signature_version": "v1",
"id": "CVE-2018-8787-e11e7457",
"signature_type": "Function",
"digest": {
"length": 1291.0,
"function_hash": "46817389793648964386179767415629149523"
}
}
]