Skip to content

oob read in channel `irp` functions

Low
bmiklautz published GHSA-hfc7-c5gv-8c2h May 29, 2020

Package

FreeRDP

Affected versions

< 2.1.0

Patched versions

2.1.0

Description

Impact

  • Out of bound read in parallel_process_irp_create, serial_process_irp_create, drive_process_irp_write, printer_process_irp_write, rdpei_recv_pdu, serial_process_irp_write
  • Affects FreeRDP clients which support parallel port, serial port, drive, printer and multitouch redirection

Patches

795842f 6b485b1 Upgrade to 2.1.0 or newer

Workarounds

Do not use /parallel, /drive, /servial, /printer or +multitouch command line option

References

Severity

Low

CVE ID

CVE-2020-11089

Weaknesses

No CWEs