SUSE-SU-2020:2272-1
Dashboard / Vulnerabilities / SUSE-SU-2020:2272-1
SUSE-SU-2020:2272-1
Summary: Security update for freerdp
Details: This update for freerdp fixes the following issues: freerdp was updated to version 2.1.2 (bsc#1171441,bsc#1173247 and jsc#ECO-2006): - CVE-2020-11017: Fixed a double free which could have denied the server's service. - CVE-2020-11018: Fixed an out of bounds read which a malicious clients could have triggered. - CVE-2020-11019: Fixed an issue which could have led to denial of service if logger was set to 'WLOG_TRACE'. - CVE-2020-11038: Fixed a buffer overflow when /video redirection was used. - CVE-2020-11039: Fixed an issue which could have allowed arbitrary memory read and write when USB redirection was enabled. - CVE-2020-11040: Fixed an out of bounds data read in clear_decompress_subcode_rlex. - CVE-2020-11041: Fixed an issue with the configuration for sound backend which could have led to server's denial of service. - CVE-2020-11043: Fixed an out of bounds read in rfx_process_message_tileset. - CVE-2020-11085: Fixed an out of bounds read in cliprdr_read_format_list. - CVE-2020-11086: Fixed an out of bounds read in ntlm_read_ntlm_v2_client_challenge. - CVE-2020-11087: Fixed an out of bounds read in ntlm_read_AuthenticateMessage. - CVE-2020-11088: Fixed an out of bounds read in ntlm_read_NegotiateMessage. - CVE-2020-11089: Fixed an out of bounds read in irp function family. - CVE-2020-11095: Fixed a global out of bounds read in update_recv_primary_order. - CVE-2020-11096: Fixed a global out of bounds read in update_read_cache_bitmap_v3_order. - CVE-2020-11097: Fixed an out of bounds read in ntlm_av_pair_get. - CVE-2020-11098: Fixed an out of bounds read in glyph_cache_put. - CVE-2020-11099: Fixed an out of bounds Read in license_read_new_or_upgrade_license_packet. - CVE-2020-11521: Fixed an out of bounds write in planar.c (bsc#1171443). - CVE-2020-11522: Fixed an out of bounds read in gdi.c (bsc#1171444). - CVE-2020-11523: Fixed an integer overflow in region.c (bsc#1171445). - CVE-2020-11524: Fixed an out of bounds write in interleaved.c (bsc#1171446). - CVE-2020-11525: Fixed an out of bounds read in bitmap.c (bsc#1171447). - CVE-2020-11526: Fixed an out of bounds read in update_recv_secondary_order (bsc#1171674). - CVE-2020-13396: Fixed an Read in ntlm_read_ChallengeMessage. - CVE-2020-13397: Fixed an out of bounds read in security_fips_decrypt due to uninitialized value. - CVE-2020-13398: Fixed an out of bounds write in crypto_rsa_common. - CVE-2020-4030: Fixed an out of bounds read in `TrioParse`. - CVE-2020-4031: Fixed a use after free in gdi_SelectObject. - CVE-2020-4032: Fixed an integer casting in `update_recv_secondary_order`. - CVE-2020-4033: Fixed an out of bound read in RLEDECOMPRESS. - Fixed an issue where freerdp failed with -fno-common (bsc#1169748). - Fixed an issue where USB redirection with FreeRDP was not working (bsc#1169679). - Fixed an issue where freerdp could not start (bsc#1129193). - Fixed an issue where copy and paste between remote host was transforming text to chinese (bsc#1004108). - Added pulse support (bsc#1090677). Additionally, the following issue was fixed: - CVE-2020-15103: Fix integer overflow due to missing input sanitation in rdpegfx channel (bsc#1174321).
References: https://www.suse.com/support/update/announcement/2020/suse-su-20202272-1/, https://bugzilla.suse.com/1004108, https://bugzilla.suse.com/1050699, https://bugzilla.suse.com/1050704, https://bugzilla.suse.com/1050708, https://bugzilla.suse.com/1050711, https://bugzilla.suse.com/1050712, https://bugzilla.suse.com/1050714, https://bugzilla.suse.com/1085416, https://bugzilla.suse.com/1087240, https://bugzilla.suse.com/1090677, https://bugzilla.suse.com/1103557, https://bugzilla.suse.com/1104918, https://bugzilla.suse.com/1112028, https://bugzilla.suse.com/1116708, https://bugzilla.suse.com/1117963, https://bugzilla.suse.com/1117964, https://bugzilla.suse.com/1117965, https://bugzilla.suse.com/1117966, https://bugzilla.suse.com/1117967, https://bugzilla.suse.com/1120507, https://bugzilla.suse.com/1129193, https://bugzilla.suse.com/1169679, https://bugzilla.suse.com/1169748, https://bugzilla.suse.com/1171441, https://bugzilla.suse.com/1171443, https://bugzilla.suse.com/1171444, https://bugzilla.suse.com/1171445, https://bugzilla.suse.com/1171446, https://bugzilla.suse.com/1171447, https://bugzilla.suse.com/1171674, https://bugzilla.suse.com/1173247, https://bugzilla.suse.com/1173605, https://bugzilla.suse.com/1174200, https://bugzilla.suse.com/1174321, https://www.suse.com/security/cve/CVE-2017-2834, https://www.suse.com/security/cve/CVE-2017-2835, https://www.suse.com/security/cve/CVE-2017-2836, https://www.suse.com/security/cve/CVE-2017-2837, https://www.suse.com/security/cve/CVE-2017-2838, https://www.suse.com/security/cve/CVE-2017-2839, https://www.suse.com/security/cve/CVE-2018-0886, https://www.suse.com/security/cve/CVE-2018-1000852, https://www.suse.com/security/cve/CVE-2018-8784, https://www.suse.com/security/cve/CVE-2018-8785, https://www.suse.com/security/cve/CVE-2018-8786, https://www.suse.com/security/cve/CVE-2018-8787, https://www.suse.com/security/cve/CVE-2018-8788, https://www.suse.com/security/cve/CVE-2018-8789, https://www.suse.com/security/cve/CVE-2020-11017, https://www.suse.com/security/cve/CVE-2020-11018, https://www.suse.com/security/cve/CVE-2020-11019, https://www.suse.com/security/cve/CVE-2020-11038, https://www.suse.com/security/cve/CVE-2020-11039, https://www.suse.com/security/cve/CVE-2020-11040, https://www.suse.com/security/cve/CVE-2020-11041, https://www.suse.com/security/cve/CVE-2020-11043, https://www.suse.com/security/cve/CVE-2020-11085, https://www.suse.com/security/cve/CVE-2020-11086, https://www.suse.com/security/cve/CVE-2020-11087, https://www.suse.com/security/cve/CVE-2020-11088, https://www.suse.com/security/cve/CVE-2020-11089, https://www.suse.com/security/cve/CVE-2020-11095, https://www.suse.com/security/cve/CVE-2020-11096, https://www.suse.com/security/cve/CVE-2020-11097, https://www.suse.com/security/cve/CVE-2020-11098, https://www.suse.com/security/cve/CVE-2020-11099, https://www.suse.com/security/cve/CVE-2020-11521, https://www.suse.com/security/cve/CVE-2020-11522, https://www.suse.com/security/cve/CVE-2020-11523, https://www.suse.com/security/cve/CVE-2020-11524, https://www.suse.com/security/cve/CVE-2020-11525, https://www.suse.com/security/cve/CVE-2020-11526, https://www.suse.com/security/cve/CVE-2020-13396, https://www.suse.com/security/cve/CVE-2020-13397, https://www.suse.com/security/cve/CVE-2020-13398, https://www.suse.com/security/cve/CVE-2020-15103, https://www.suse.com/security/cve/CVE-2020-4030, https://www.suse.com/security/cve/CVE-2020-4031, https://www.suse.com/security/cve/CVE-2020-4032, https://www.suse.com/security/cve/CVE-2020-4033
Affected packages
Package
Name: freerdp
Purl: pkg:rpm/suse/freerdp&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5
Affected ranges
Type: ECOSYSTEM
Events:
