Unrated severityNVD Advisory· Published Jun 22, 2020· Updated Aug 4, 2024
OOB read in `TrioParse` in FreeRDP
CVE-2020-4030
Description
In FreeRDP before version 2.1.2, there is an out of bounds read in TrioParse. Logging might bypass string length checks due to an integer overflow. This is fixed in version 2.1.2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
10- osv-coords8 versionspkg:rpm/almalinux/freerdp-develpkg:rpm/opensuse/freerdp2&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/freerdp&distro=openSUSE%20Leap%2015.1pkg:rpm/suse/freerdp&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5pkg:rpm/suse/freerdp&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012%20SP5pkg:rpm/suse/freerdp&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP1pkg:rpm/suse/freerdp&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP2pkg:rpm/suse/vinagre&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012%20SP5
< 2:2.2.0-1.el8+ 7 more
- (no CPE)range: < 2:2.2.0-1.el8
- (no CPE)range: < 2.4.0-2.1
- (no CPE)range: < 2.1.2-lp151.5.6.1
- (no CPE)range: < 2.1.2-12.20.1
- (no CPE)range: < 2.1.2-12.20.1
- (no CPE)range: < 2.1.2-10.15.1
- (no CPE)range: < 2.1.2-15.7.1
- (no CPE)range: < 3.20.2-16.3.3
Patches
Vulnerability mechanics
References
8- lists.opensuse.org/opensuse-security-announce/2020-07/msg00080.htmlmitrevendor-advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6Y35HBHG2INICLSGCIKNAR7GCXEHQACQ/mitrevendor-advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XOZLH35OJWIQLM7FYDXAP2EAUBDXE76V/mitrevendor-advisory
- usn.ubuntu.com/4481-1/mitrevendor-advisory
- lists.debian.org/debian-lts-announce/2023/10/msg00008.htmlmitremailing-list
- www.freerdp.com/2020/06/22/2_1_2-releasedmitre
- github.com/FreeRDP/FreeRDP/commit/05cd9ea2290d23931f615c1b004d4b2e69074e27mitre
- github.com/FreeRDP/FreeRDP/security/advisories/GHSA-fjr5-97f5-qq98mitre
News mentions
0No linked articles in our index yet.