CVE-2020-15103

NameCVE-2020-15103
DescriptionIn FreeRDP less than or equal to 2.1.2, an integer overflow exists due to missing input sanitation in rdpegfx channel. All FreeRDP clients are affected. The input rectangles from the server are not checked against local surface coordinates and blindly accepted. A malicious server can send data that will crash the client later on (invalid length arguments to a `memcpy`) This has been fixed in 2.2.0. As a workaround, stop using command line arguments /gfx, /gfx-h264 and /network:auto
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-3606-1
Debian Bugs965979

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
freerdp (PTS)jessie, jessie (lts)1.1.0~git20140921.1.440916e+dfsg1-13~deb8u3vulnerable
stretch (security)1.1.0~git20140921.1.440916e+dfsg1-13+deb9u4fixed
stretch (lts), stretch1.1.0~git20140921.1.440916e+dfsg1-13+deb9u6fixed
freerdp2 (PTS)buster (security), buster, buster (lts)2.3.0+dfsg1-2+deb10u4fixed
bullseye2.3.0+dfsg1-2+deb11u1fixed
bookworm2.10.0+dfsg1-1fixed
sid, trixie2.11.7+dfsg1-4fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
freerdpsourcejessie(unfixed)end-of-life
freerdpsourcestretch(not affected)
freerdpsource(unstable)(unfixed)
freerdp2sourcebuster2.3.0+dfsg1-2+deb10u3DLA-3606-1
freerdp2source(unstable)2.2.0+dfsg1-1965979

Notes

[stretch] - freerdp <not-affected> (Vulnerable gfx code not present)
https://github.com/FreeRDP/FreeRDP/pull/6381
https://github.com/FreeRDP/FreeRDP/commit/be8c8640ead04b1e4fc9176c504bf688351c8924 (stable-2.0)
https://github.com/FreeRDP/FreeRDP/commit/da684f5335c2b3b726a39f3c091ce804e55f4f8e (stable-2.0)

Search for package or bug name: Reporting problems