CVE-2020-4030

NameCVE-2020-4030
DescriptionIn FreeRDP before version 2.1.2, there is an out of bounds read in TrioParse. Logging might bypass string length checks due to an integer overflow. This is fixed in version 2.1.2.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-3606-1, ELA-717-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
freerdp (PTS)jessie, jessie (lts)1.1.0~git20140921.1.440916e+dfsg1-13~deb8u3vulnerable
stretch (security)1.1.0~git20140921.1.440916e+dfsg1-13+deb9u4vulnerable
stretch (lts), stretch1.1.0~git20140921.1.440916e+dfsg1-13+deb9u6fixed
freerdp2 (PTS)buster2.0.0~git20190204.1.2693389a+dfsg1-1+deb10u2vulnerable
buster (security)2.3.0+dfsg1-2+deb10u4fixed
bullseye2.3.0+dfsg1-2+deb11u1fixed
bookworm2.10.0+dfsg1-1fixed
sid, trixie2.11.5+dfsg1-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
freerdpsourcewheezy(unfixed)end-of-life
freerdpsourcejessie(unfixed)end-of-life
freerdpsourcestretch1.1.0~git20140921.1.440916e+dfsg1-13+deb9u5ELA-717-1
freerdpsource(unstable)(unfixed)
freerdp2sourcebuster2.3.0+dfsg1-2+deb10u3DLA-3606-1
freerdp2source(unstable)2.1.2+dfsg1-1

Notes

[stretch] - freerdp <no-dsa> (Minor issue)
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-fjr5-97f5-qq98

Search for package or bug name: Reporting problems