openSUSE-SU-2020:1090-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2020:1090-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2020:1090-1
Related
Published
2020-07-26T18:19:38Z
Modified
2020-07-26T18:19:38Z
Summary
Security update for freerdp
Details

This update for freerdp fixes the following issues:

frerdp was updated to version 2.1.2 (bsc#1171441,bsc#1173247 and jsc#ECO-2006):

  • CVE-2020-11017: Fixed a double free which could have denied the server's service.
  • CVE-2020-11018: Fixed an out of bounds read which a malicious clients could have triggered.
  • CVE-2020-11019: Fixed an issue which could have led to denial of service if logger was set to 'WLOG_TRACE'.
  • CVE-2020-11038: Fixed a buffer overflow when /video redirection was used.
  • CVE-2020-11039: Fixed an issue which could have allowed arbitrary memory read and write when USB redirection was enabled.
  • CVE-2020-11040: Fixed an out of bounds data read in cleardecompresssubcode_rlex.
  • CVE-2020-11041: Fixed an issue with the configuration for sound backend which could have led to server's denial of service.
  • CVE-2020-11043: Fixed an out of bounds read in rfxprocessmessage_tileset.
  • CVE-2020-11085: Fixed an out of bounds read in cliprdrreadformat_list.
  • CVE-2020-11086: Fixed an out of bounds read in ntlmreadntlmv2client_challenge.
  • CVE-2020-11087: Fixed an out of bounds read in ntlmreadAuthenticateMessage.
  • CVE-2020-11088: Fixed an out of bounds read in ntlmreadNegotiateMessage.
  • CVE-2020-11089: Fixed an out of bounds read in irp function family.
  • CVE-2020-11095: Fixed a global out of bounds read in updaterecvprimary_order.
  • CVE-2020-11096: Fixed a global out of bounds read in updatereadcachebitmapv3_order.
  • CVE-2020-11097: Fixed an out of bounds read in ntlmavpair_get.
  • CVE-2020-11098: Fixed an out of bounds read in glyphcacheput.
  • CVE-2020-11099: Fixed an out of bounds Read in licensereadneworupgradelicensepacket.
  • CVE-2020-11521: Fixed an out of bounds write in planar.c (bsc#1171443).
  • CVE-2020-11522: Fixed an out of bounds read in gdi.c (bsc#1171444).
  • CVE-2020-11523: Fixed an integer overflow in region.c (bsc#1171445).
  • CVE-2020-11524: Fixed an out of bounds write in interleaved.c (bsc#1171446).
  • CVE-2020-11525: Fixed an out of bounds read in bitmap.c (bsc#1171447).
  • CVE-2020-11526: Fixed an out of bounds read in updaterecvsecondary_order (bsc#1171674).
  • CVE-2020-13396: Fixed an Read in ntlmreadChallengeMessage.
  • CVE-2020-13397: Fixed an out of bounds read in securityfipsdecrypt due to uninitialized value.
  • CVE-2020-13398: Fixed an out of bounds write in cryptorsacommon.
  • CVE-2020-4030: Fixed an out of bounds read in TrioParse.
  • CVE-2020-4031: Fixed a use after free in gdi_SelectObject.
  • CVE-2020-4032: Fixed an integer casting in update_recv_secondary_order.
  • CVE-2020-4033: Fixed an out of bound read in RLEDECOMPRESS.
  • Fixed an issue where freerdp failed with -fno-common (bsc#1169748).
  • Fixed an issue where USB redirection with FreeRDP was not working (bsc#1169679).

This update was imported from the SUSE:SLE-15-SP1:Update update project.

References

Affected packages

openSUSE:Leap 15.1 / freerdp

Package

Name
freerdp
Purl
pkg:rpm/opensuse/freerdp&distro=openSUSE%20Leap%2015.1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.1.2-lp151.5.6.1

Ecosystem specific

{
    "binaries": [
        {
            "libuwac0-0": "2.1.2-lp151.5.6.1",
            "freerdp-devel": "2.1.2-lp151.5.6.1",
            "libwinpr2": "2.1.2-lp151.5.6.1",
            "freerdp-proxy": "2.1.2-lp151.5.6.1",
            "uwac0-0-devel": "2.1.2-lp151.5.6.1",
            "freerdp-server": "2.1.2-lp151.5.6.1",
            "libfreerdp2": "2.1.2-lp151.5.6.1",
            "freerdp": "2.1.2-lp151.5.6.1",
            "freerdp-wayland": "2.1.2-lp151.5.6.1",
            "winpr2-devel": "2.1.2-lp151.5.6.1"
        }
    ]
}