Lucene search

K
redhatcveRedhat.comRH:CVE-2020-13398
HistoryMay 28, 2020 - 3:55 p.m.

CVE-2020-13398

2020-05-2815:55:59
redhat.com
access.redhat.com
13

0.002 Low

EPSS

Percentile

55.1%

An issue was found in freerdp’s libfreerdp/crypto/crypto.c, in versions before 2.1.1, where buffer access with an incorrect length value, leads to an out-of-bounds write. This flaw allows a remote, unauthenticated, attacker running an RDP server, or a local attacker, using a specially crafted certificate, to cause an out-of-bounds write into client process memory, corrupting the integrity of the data used in the RSA encryption functionality, or causing a denial of service.

Mitigation

To mitigate this flaw, only make connection attempts to trusted RDP servers from the RDP client application.