Mageia 2019-0012: freerdp security update
Summary
Eyal Itkin discovered FreeRDP incorrectly handled certain stream
encodings. A malicious server could use this issue to cause FreeRDP to
crash, resulting in a denial of service, or possibly execute arbitrary
code (CVE-2018-8784, CVE-2018-8785).
Eyal Itkin discovered FreeRDP incorrectly handled bitmaps. A malicious
server could use this issue to cause FreeRDP to crash, resulting in a
denial of service, or possibly execute arbitrary code (CVE-2018-8786,
CVE-2018-8787).
Eyal Itkin discovered FreeRDP incorrectly handled certain stream
encodings. A malicious server could use this issue to cause FreeRDP to
crash, resulting in a denial of service, or possibly execute arbitrary
code (CVE-2018-8788).
Eyal Itkin discovered FreeRDP incorrectly handled NTLM authentication. A
malicious server could use this issue to cause FreeRDP to crash,
resulting in a denial of service, or possibly execute arbitrary code
(CVE-2018-8789).
References
- https://bugs.mageia.org/show_bug.cgi?id=24074
- https://ubuntu.com/security/notices/USN-3845-1
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-8784
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-8785
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-8786
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-8787
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-8788
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-8789
Resolution
MGASA-2019-0012 - Updated freerdp packages fix security vulnerabilities
SRPMS
- 6/core/freerdp-2.0.0-0.rc4.1.mga6