CVE-2020-11045

In FreeRDP after 1.0 and before 2.0.0, there is an out-of-bound read in in update_read_bitmap_data that allows client memory to be read to an image buffer. The result displayed on screen as colour.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
2.2 LOW
NETWORK
HIGH
HIGH
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 37%
Affected Products (NVD)
VendorProductVersion
freerdpfreerdp
1.1.0 ≤
𝑥
< 2.0.0
debiandebian_linux
9.0
debiandebian_linux
10.0
canonicalubuntu_linux
16.04
canonicalubuntu_linux
18.04
canonicalubuntu_linux
19.10
canonicalubuntu_linux
20.04
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
freerdp2
bookworm
2.10.0+dfsg1-1
fixed
bullseye
2.3.0+dfsg1-2+deb11u1
fixed
sid
2.11.7+dfsg1-4
fixed
trixie
2.11.7+dfsg1-4
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
freerdp
bionic
Fixed 1.1.0~git20140921.1.440916e+dfsg1-15ubuntu1.18.04.2
released
eoan
dne
focal
dne
groovy
dne
trusty
dne
xenial
Fixed 1.1.0~git20140921.1.440916e+dfsg1-5ubuntu1.4
released
freerdp2
bionic
Fixed 2.1.1+dfsg1-0ubuntu0.18.04.1
released
eoan
Fixed 2.1.1+dfsg1-0ubuntu0.19.10.1
released
focal
Fixed 2.1.1+dfsg1-0ubuntu0.20.04.1
released
groovy
not-affected
trusty
dne
xenial
dne
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
freerdp
RHEL 7
0:2.1.1-2.el7
fixed
RHEL 8
2:2.1.1-1.el8
fixed
freerdp-devel
RHEL 7
0:2.1.1-2.el7
fixed
RHEL 8
2:2.1.1-1.el8
fixed
freerdp-libs
RHEL 7
0:2.1.1-2.el7
fixed
RHEL 8
2:2.1.1-1.el8
fixed
libwinpr
RHEL 7
0:2.1.1-2.el7
fixed
RHEL 8
2:2.1.1-1.el8
fixed
libwinpr-devel
RHEL 7
0:2.1.1-2.el7
fixed
RHEL 8
2:2.1.1-1.el8
fixed
vinagre
RHEL 8
0:3.22.0-23.el8
fixed