Unrated severityNVD Advisory· Published May 24, 2011· Updated Apr 29, 2026
CVE-2011-1595
CVE-2011-1595
Description
Directory traversal vulnerability in the disk_create function in disk.c in rdesktop before 1.7.0, when disk redirection is enabled, allows remote RDP servers to read or overwrite arbitrary files via a .. (dot dot) in a pathname.
Affected products
9cpe:2.3:a:rdesktop:rdesktop:*:*:*:*:*:*:*:*+ 8 more
- cpe:2.3:a:rdesktop:rdesktop:*:*:*:*:*:*:*:*range: <=1.6.0
- cpe:2.3:a:rdesktop:rdesktop:1.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:rdesktop:rdesktop:1.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:rdesktop:rdesktop:1.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:rdesktop:rdesktop:1.3.0:*:*:*:*:*:*:*
- cpe:2.3:a:rdesktop:rdesktop:1.3.1:*:*:*:*:*:*:*
- cpe:2.3:a:rdesktop:rdesktop:1.4.0:*:*:*:*:*:*:*
- cpe:2.3:a:rdesktop:rdesktop:1.4.1:*:*:*:*:*:*:*
- cpe:2.3:a:rdesktop:rdesktop:1.5.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
15- rdesktop.svn.sourceforge.net/viewvc/rdesktopnvdPatch
- sourceforge.net/projects/rdesktop/files/rdesktop/1.7.0/rdesktop-1.7.0.tar.gz/downloadnvdPatch
- bugzilla.redhat.com/show_bug.cginvdExploitPatch
- lists.fedoraproject.org/pipermail/package-announce/2011-June/061170.htmlnvd
- lists.fedoraproject.org/pipermail/package-announce/2011-June/061309.htmlnvd
- lists.fedoraproject.org/pipermail/package-announce/2011-June/061316.htmlnvd
- secunia.com/advisories/44881nvd
- secunia.com/advisories/51023nvd
- security.gentoo.org/glsa/glsa-201210-03.xmlnvd
- securitytracker.com/idnvd
- sourceforge.net/mailarchive/message.phpnvd
- www.mandriva.com/security/advisoriesnvd
- www.securityfocus.com/bid/47419nvd
- www.ubuntu.com/usn/USN-1136-1nvd
- rhn.redhat.com/errata/RHSA-2011-0506.htmlnvd
News mentions
0No linked articles in our index yet.