Low severity3.5NVD Advisory· Published Jul 27, 2020· Updated Jun 17, 2026
CVE-2020-15103
CVE-2020-15103
Description
In FreeRDP less than or equal to 2.1.2, an integer overflow exists due to missing input sanitation in rdpegfx channel. All FreeRDP clients are affected. The input rectangles from the server are not checked against local surface coordinates and blindly accepted. A malicious server can send data that will crash the client later on (invalid length arguments to a memcpy) This has been fixed in 2.2.0. As a workaround, stop using command line arguments /gfx, /gfx-h264 and /network:auto
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
17cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:esm:*:*:*+ 1 more
- cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:esm:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*
cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
- osv-coords8 versionspkg:rpm/almalinux/freerdp-develpkg:rpm/opensuse/freerdp&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/freerdp2&distro=openSUSE%20Tumbleweedpkg:rpm/suse/freerdp&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5pkg:rpm/suse/freerdp&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012%20SP5pkg:rpm/suse/freerdp&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP1pkg:rpm/suse/freerdp&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP2pkg:rpm/suse/vinagre&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012%20SP5
< 2:2.2.0-1.el8+ 7 more
- (no CPE)range: < 2:2.2.0-1.el8
- (no CPE)range: < 2.1.2-lp151.5.9.1
- (no CPE)range: < 2.4.0-2.1
- (no CPE)range: < 2.1.2-12.20.1
- (no CPE)range: < 2.1.2-12.20.1
- (no CPE)range: < 2.1.2-10.18.1
- (no CPE)range: < 2.1.2-15.10.1
- (no CPE)range: < 3.20.2-16.3.3
Patches
Vulnerability mechanics
References
8- github.com/FreeRDP/FreeRDP/pull/6382nvdPatchThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2020-09/msg00010.htmlnvdMailing ListThird Party Advisory
- github.com/FreeRDP/FreeRDP/blob/616af2d5b86dc24c7b3e89870dbcffd841d9a535/ChangeLognvdRelease NotesThird Party Advisory
- github.com/FreeRDP/FreeRDP/security/advisories/GHSA-4r38-6hq7-j3j9nvdThird Party Advisory
- lists.debian.org/debian-lts-announce/2023/10/msg00008.htmlnvdMailing ListThird Party Advisory
- usn.ubuntu.com/4481-1/nvdThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6Y35HBHG2INICLSGCIKNAR7GCXEHQACQ/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XOZLH35OJWIQLM7FYDXAP2EAUBDXE76V/nvd
News mentions
0No linked articles in our index yet.