Multiple integer overflows in client/X11/xf_graphics.c in FreeRDP allow remote attackers...
Vulnerability Description
Multiple integer overflows in client/X11/xf_graphics.c in FreeRDP allow remote attackers to have an unspecified impact via the width and height to the (1) xf_Pointer_New or (2) xf_Bitmap_Decompress function, which causes an incorrect amount of memory to be allocated.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2014-0250
Credits & Attribution
No credits recorded in the NVD database.
References
- http://lists.opensuse.org/opensuse-updates/2014-07/msg00008.html
- https://github.com/FreeRDP/FreeRDP/issues/1871
- https://github.com/FreeRDP/FreeRDP/pull/1874
- https://bugzilla.redhat.com/show_bug.cgi?id=998934
- http://security.gentoo.org/glsa/glsa-201412-18.xml
- http://seclists.org/oss-sec/2014/q2/365
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:171
- http://advisories.mageia.org/MGASA-2014-0287.html
- http://www.securityfocus.com/bid/67670
More from freerdp
View All →Affected Vendor
freerdp
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.