Oval Definition:oval:com.redhat.rhsa:def:20211849
Revision Date:2021-05-18Version:636
Title:RHSA-2021:1849: freerdp security, bug fix, and enhancement update (Moderate)
Description:FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. The xfreerdp client can connect to RDP servers such as Microsoft Windows machines, xrdp, and VirtualBox.

  • The following packages have been upgraded to a later upstream version: freerdp (2.2.0). (BZ#1881971)

    Security Fix(es):

  • freerdp: out of bounds read in TrioParse (CVE-2020-4030)

  • freerdp: out of bound reads resulting in accessing memory location outside of static array PRIMARY_DRAWING_ORDER_FIELD_BYTES (CVE-2020-11095)

  • freerdp: out of bounds read in PRIMARY_DRAWING_ORDER_FIELD_BYTES (CVE-2020-11097)

  • freerdp: out of bounds read in license_read_new_or_upgrade_license_packet (CVE-2020-11099)

  • freerdp: integer overflow due to missing input sanitation in rdpegfx channel (CVE-2020-15103)

  • freerdp: out-of-bounds read in RLEDECOMPRESS (CVE-2020-4033)

  • freerdp: out-of-bound read in update_read_cache_bitmap_v3_order (CVE-2020-11096)

  • freerdp: out-of-bound read in glyph_cache_put (CVE-2020-11098)

    For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

    Additional Changes:

    For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.4 Release Notes linked from the References section.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2020-11095
    CVE-2020-11096
    CVE-2020-11097
    CVE-2020-11098
    CVE-2020-11099
    CVE-2020-15103
    CVE-2020-4030
    CVE-2020-4033
    RHSA-2021:1849
    Platform(s):Red Hat Enterprise Linux 8
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 8 is installed
  • OR Red Hat CoreOS 4 is installed
  • AND
  • freerdp is earlier than 2:2.2.0-1.el8
  • AND freerdp is signed with Red Hat redhatrelease2 key
  • freerdp-devel is earlier than 2:2.2.0-1.el8
  • AND freerdp-devel is signed with Red Hat redhatrelease2 key
  • freerdp-libs is earlier than 2:2.2.0-1.el8
  • AND freerdp-libs is signed with Red Hat redhatrelease2 key
  • libwinpr is earlier than 2:2.2.0-1.el8
  • AND libwinpr is signed with Red Hat redhatrelease2 key
  • libwinpr-devel is earlier than 2:2.2.0-1.el8
  • AND libwinpr-devel is signed with Red Hat redhatrelease2 key
  • BACK