CVE-2019-17178
04.10.2019, 17:15
HuffmanTree_makeFromFrequencies in lodepng.c in LodePNG through 2019-09-28, as used in WinPR in FreeRDP and other products, has a memory leak because a supplied realloc pointer (i.e., the first argument to realloc) is also used for a realloc return value.Enginsight
Vendor | Product | Version |
---|---|---|
freerdp | freerdp | 𝑥 ≤ 1.0.2 |
freerdp | freerdp | 1.1.0:beta1 |
lodev | lodepng | 𝑥 ≤ 2019-09-28 |
opensuse | leap | 15.0 |
opensuse | leap | 15.1 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
freerdp |
| ||||||||||||||||||||||||
freerdp2 |
|
Common Weakness Enumeration
References