rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function process_bitmap_updates() that results in a Denial of Service (segfault).
The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.
The product reads data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/106938 | third party advisory vdb entry |
https://github.com/rdesktop/rdesktop/commit/4dca546d04321a610c1835010b5dad85163b65e1 | third party advisory patch |
https://security.gentoo.org/glsa/201903-06 | third party advisory vendor advisory |
https://research.checkpoint.com/reverse-rdp-attack-code-execution-on-rdp-clients/ | third party advisory |
https://www.debian.org/security/2019/dsa-4394 | third party advisory vendor advisory |
https://lists.debian.org/debian-lts-announce/2019/02/msg00030.html | third party advisory mailing list |
http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00040.html | vendor advisory |