Description
FreeRDP prior to version 2.0.0-rc4 contains an Out-Of-Bounds Write of up to 4 bytes in function nsc_rle_decode() that results in a memory corruption and possibly even a remote code execution.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1666-1 | freerdp security update |
EUVD |
EUVD-2018-20397 | FreeRDP prior to version 2.0.0-rc4 contains an Out-Of-Bounds Write of up to 4 bytes in function nsc_rle_decode() that results in a memory corruption and possibly even a remote code execution. |
Ubuntu USN |
USN-3845-1 | FreeRDP vulnerabilities |
Ubuntu USN |
USN-3845-2 | FreeRDP vulnerabilities |
References
History
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: checkpoint
Published:
Updated: 2024-09-16T17:28:15.906Z
Reserved: 2018-03-19T00:00:00.000Z
Link: CVE-2018-8788
No data.
Status : Modified
Published: 2018-11-29T18:29:00.990
Modified: 2024-11-21T04:14:18.937
Link: CVE-2018-8788
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD
Ubuntu USN