SUSE-SU-2019:0134-1
Dashboard / Vulnerabilities / SUSE-SU-2019:0134-1
SUSE-SU-2019:0134-1
Summary: Security update for freerdp
Details: This update for freerdp fixes the following issues: Security issues fixed: - CVE-2018-0886: Fix a remote code execution vulnerability (CredSSP) (bsc#1085416, bsc#1087240, bsc#1104918) - CVE-2018-8789: Fix several denial of service vulnerabilities in the in the NTLM Authentication module (bsc#1117965) - CVE-2018-8785: Fix a potential remote code execution vulnerability in the zgfx_decompress function (bsc#1117967) - CVE-2018-8786: Fix a potential remote code execution vulnerability in the update_read_bitmap_update function (bsc#1117966) - CVE-2018-8787: Fix a potential remote code execution vulnerability in the gdi_Bitmap_Decompress function (bsc#1117964) - CVE-2018-8788: Fix a potential remote code execution vulnerability in the nsc_rle_decode function (bsc#1117963) - CVE-2018-8784: Fix a potential remote code execution vulnerability in the zgfx_decompress_segment function (bsc#1116708) - CVE-2018-1000852: Fixed a remote memory access in the drdynvc_process_capability_request function (bsc#1120507)
References: https://www.suse.com/support/update/announcement/2019/suse-su-20190134-1/, https://bugzilla.suse.com/1085416, https://bugzilla.suse.com/1087240, https://bugzilla.suse.com/1104918, https://bugzilla.suse.com/1116708, https://bugzilla.suse.com/1117963, https://bugzilla.suse.com/1117964, https://bugzilla.suse.com/1117965, https://bugzilla.suse.com/1117966, https://bugzilla.suse.com/1117967, https://bugzilla.suse.com/1120507, https://www.suse.com/security/cve/CVE-2018-0886, https://www.suse.com/security/cve/CVE-2018-1000852, https://www.suse.com/security/cve/CVE-2018-8784, https://www.suse.com/security/cve/CVE-2018-8785, https://www.suse.com/security/cve/CVE-2018-8786, https://www.suse.com/security/cve/CVE-2018-8787, https://www.suse.com/security/cve/CVE-2018-8788, https://www.suse.com/security/cve/CVE-2018-8789
Affected packages
Package
Name: freerdp
Purl: pkg:rpm/suse/freerdp&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3
Affected ranges
Type: ECOSYSTEM
Events:
