Back to Database
Status published
Low
CVE-2020-11048
Out-of-bounds Read in FreeRDPrdp_read_flow_control_pdu
Vulnerability Description
In FreeRDP after 1.0 and before 2.0.0, there is an out-of-bounds read. It only allows to abort a session. No data extraction is possible. This has been fixed in 2.0.0.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-11048
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-hv8w-f2hx-5gcv
- https://github.com/FreeRDP/FreeRDP/issues/6007
- https://github.com/FreeRDP/FreeRDP/commit/9301bfe730c66180263248b74353daa99f5a969b
- https://usn.ubuntu.com/4379-1/
- https://usn.ubuntu.com/4382-1/
- https://lists.debian.org/debian-lts-announce/2020/08/msg00054.html
- https://lists.debian.org/debian-lts-announce/2023/10/msg00008.html
More from FreeRDP
View All →CVE-2025-68118
Potential Heap Out-of-Bounds Read in freerdp_certificate_data_hash_ via Unsafe _snprintf Usage
Medium
6.6
CVE-2024-32662
FreeRDP rdp_redirection_read_base64_wchar out of bound read
High
7.5
CVE-2024-32661
FreeRDP rdp_write_logon_info_v1 NULL access
High
7.5
CVE-2024-32660
FreeRDP zgfx_decompress out of memory vulnerability
High
7.5
CVE-2024-32659
freerdp_image_copy out of bound read
Critical
9.8
Affected Vendor
FreeRDP
View all reports →Affected Software
FreeRDP
Vulnerable Versions:
> 1.0, < 2.0.0
Timeline
Official Publish:
May 7th, 2020
Last Modified:
August 4th, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L