Back to Database
Status published
Low
CVE-2020-11089
Out-of-bound read in FreeRDP
Vulnerability Description
In FreeRDP before 2.1.0, there is an out-of-bound read in irp functions (parallel_process_irp_create, serial_process_irp_create, drive_process_irp_write, printer_process_irp_write, rdpei_recv_pdu, serial_process_irp_write). This has been fixed in 2.1.0.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-11089
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-hfc7-c5gv-8c2h
- https://github.com/FreeRDP/FreeRDP/commit/6b485b146a1b9d6ce72dfd7b5f36456c166e7a16
- https://github.com/FreeRDP/FreeRDP/commit/795842f4096501fcefc1a7f535ccc8132feb31d7
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00080.html
- https://lists.debian.org/debian-lts-announce/2023/10/msg00008.html
More from FreeRDP
View All →CVE-2025-68118
Potential Heap Out-of-Bounds Read in freerdp_certificate_data_hash_ via Unsafe _snprintf Usage
Medium
6.6
CVE-2024-32662
FreeRDP rdp_redirection_read_base64_wchar out of bound read
High
7.5
CVE-2024-32661
FreeRDP rdp_write_logon_info_v1 NULL access
High
7.5
CVE-2024-32660
FreeRDP zgfx_decompress out of memory vulnerability
High
7.5
CVE-2024-32659
freerdp_image_copy out of bound read
Critical
9.8
Affected Vendor
FreeRDP
View all reports →Affected Software
FreeRDP
Vulnerable Versions:
< 2.1.0
Timeline
Official Publish:
May 29th, 2020
Last Modified:
August 4th, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N