SB2019052836 - Out-of-bounds read in rdesktop (Alpine package)
Published: May 28, 2019
Security Bulletin ID
SB2019052836
Severity
Medium
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Denial of service
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2018-20175)
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
rdesktop versions up to and including v1.8.3 contains several Integer Signedness errors that lead to Out-Of-Bounds Reads in the file mcs.c and result in a Denial of Service (segfault).
Remediation
Install update from vendor's website.