CVE-2020-4030

In FreeRDP before version 2.1.2, there is an out of bounds read in TrioParse. Logging might bypass string length checks due to an integer overflow. This is fixed in version 2.1.2.
References
Link Resource
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00080.html Mailing List Third Party Advisory
http://www.freerdp.com/2020/06/22/2_1_2-released Release Notes Vendor Advisory
https://github.com/FreeRDP/FreeRDP/commit/05cd9ea2290d23931f615c1b004d4b2e69074e27 Patch Third Party Advisory
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-fjr5-97f5-qq98 Third Party Advisory
https://lists.debian.org/debian-lts-announce/2023/10/msg00008.html Mailing List Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6Y35HBHG2INICLSGCIKNAR7GCXEHQACQ/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XOZLH35OJWIQLM7FYDXAP2EAUBDXE76V/
https://usn.ubuntu.com/4481-1/ Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00080.html Mailing List Third Party Advisory
http://www.freerdp.com/2020/06/22/2_1_2-released Release Notes Vendor Advisory
https://github.com/FreeRDP/FreeRDP/commit/05cd9ea2290d23931f615c1b004d4b2e69074e27 Patch Third Party Advisory
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-fjr5-97f5-qq98 Third Party Advisory
https://lists.debian.org/debian-lts-announce/2023/10/msg00008.html Mailing List Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6Y35HBHG2INICLSGCIKNAR7GCXEHQACQ/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XOZLH35OJWIQLM7FYDXAP2EAUBDXE76V/
https://usn.ubuntu.com/4481-1/ Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*

Configuration 4 (hide)

OR cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:esm:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*

Configuration 5 (hide)

cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

History

21 Nov 2024, 05:32

Type Values Removed Values Added
References () http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00080.html - Mailing List, Third Party Advisory () http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00080.html - Mailing List, Third Party Advisory
References () http://www.freerdp.com/2020/06/22/2_1_2-released - Release Notes, Vendor Advisory () http://www.freerdp.com/2020/06/22/2_1_2-released - Release Notes, Vendor Advisory
References () https://github.com/FreeRDP/FreeRDP/commit/05cd9ea2290d23931f615c1b004d4b2e69074e27 - Patch, Third Party Advisory () https://github.com/FreeRDP/FreeRDP/commit/05cd9ea2290d23931f615c1b004d4b2e69074e27 - Patch, Third Party Advisory
References () https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-fjr5-97f5-qq98 - Third Party Advisory () https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-fjr5-97f5-qq98 - Third Party Advisory
References () https://lists.debian.org/debian-lts-announce/2023/10/msg00008.html - Mailing List, Third Party Advisory () https://lists.debian.org/debian-lts-announce/2023/10/msg00008.html - Mailing List, Third Party Advisory
References () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6Y35HBHG2INICLSGCIKNAR7GCXEHQACQ/ - () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6Y35HBHG2INICLSGCIKNAR7GCXEHQACQ/ -
References () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XOZLH35OJWIQLM7FYDXAP2EAUBDXE76V/ - () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XOZLH35OJWIQLM7FYDXAP2EAUBDXE76V/ -
References () https://usn.ubuntu.com/4481-1/ - Third Party Advisory () https://usn.ubuntu.com/4481-1/ - Third Party Advisory
CVSS v2 : 6.4
v3 : 6.5
v2 : 6.4
v3 : 3.5

07 Oct 2021, 17:22

Type Values Removed Values Added
CPE cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
References (UBUNTU) https://usn.ubuntu.com/4481-1/ - (UBUNTU) https://usn.ubuntu.com/4481-1/ - Third Party Advisory
CWE CWE-125 CWE-190

Information

Published : 2020-06-22 22:15

Updated : 2024-11-21 05:32


NVD link : CVE-2020-4030

Mitre link : CVE-2020-4030

CVE.ORG link : CVE-2020-4030


JSON object : View

Products Affected

fedoraproject

  • fedora

opensuse

  • leap

canonical

  • ubuntu_linux

freerdp

  • freerdp

debian

  • debian_linux
CWE
CWE-125

Out-of-bounds Read

CWE-190

Integer Overflow or Wraparound