Release date:
Updated on:
Affected Systems:
FreeRDP 1.0.2-4
Description:
--------------------------------------------------------------------------------
Bugtraq id: 67670
CVE (CAN) ID: CVE-2014-0250
FreeRDP is the client of the Remote Desktop Protocol.
FreeRDP has the integer overflow vulnerability in the memory allocation of client/X11/xf_graphics.c. Remote attackers can exploit this vulnerability to execute arbitrary code in the context of the affected application or cause DOS.
<* Source: Florian weian (Weimer@CERT.Uni-Stuttgart.DE)
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
FreeRDP
-------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Https://github.com/FreeRDP/FreeRDP/issues/1871
This article permanently updates the link address: