In FreeRDP after 1.0 and before 2.0.0, there is an out-of-bound read in in updatereadbitmap_data that allows client memory to be read to an image buffer. The result displayed on screen as colour.
[
{
"source": "https://github.com/freerdp/freerdp/commit/f8890a645c221823ac133dbf991f8a65ae50d637",
"signature_version": "v1",
"digest": {
"function_hash": "206436341201980652058609057959198552998",
"length": 1297.0
},
"target": {
"function": "update_read_bitmap_data",
"file": "libfreerdp/core/update.c"
},
"id": "CVE-2020-11045-28b89200",
"deprecated": false,
"signature_type": "Function"
},
{
"source": "https://github.com/freerdp/freerdp/commit/f8890a645c221823ac133dbf991f8a65ae50d637",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"174082662618401205352853601715769749832",
"84560628654313816427147087026633431051",
"182426011417203487958277892954071378642",
"308865737782997131972517872718766365445"
]
},
"target": {
"file": "libfreerdp/core/update.c"
},
"id": "CVE-2020-11045-8488ed58",
"deprecated": false,
"signature_type": "Line"
}
]