Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Fedora 28: Update for FreeRDP Critical Buffer Overflow Issue

fedora
Calendar Grey April 4, 2019
Dist Fedora Esm H88
Critical updates for FreeRDP addressing out-of-bounds read and buffer overflow issues released for Fedora 28, strengthening system security.
FreeRDP fix for CVE-2018-1000852, Remmina bugfix update and rebuilds for updated FreeRDP.

Summary

The xfreerdp & wlfreerdp Remote Desktop Protocol (RDP) clients from the FreeRDP

project.

xfreerdp & wlfreerdp can connect to RDP servers such as Microsoft Windows

machines, xrdp and VirtualBox.

FreeRDP fix for CVE-2018-1000852, Remmina bugfix update and rebuilds for updated

FreeRDP.

* Wed Mar 6 2019 Simone Caronni - 2:2.0.0-49.20190304git435872b

- Fix for GFX color depth (Windows 10).

* Thu Feb 28 2019 Simone Caronni - 2:2.0.0-48.20190228gitce386c8

- Update to latest snapshot post rc4.

- CVE-2018-1000852 (#1661642).

* Thu Jan 31 2019 Fedora Release Engineering - 2:2.0.0-47.rc4.1

- Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild

* Thu Nov 29 2018 Ondrej Holy - 2:2.0.0-47.rc4

- Update to 2.0.0-rc4

* Mon Oct 15 2018 Simone Caronni - 2:2.0.0-46.20181008git00af869

- Enable Xtest option (#1559606).

* Mon Oct 15 2018 Simone Caronni - 2:2.0.0-45.20181008git00af869

- Update to last snapshot post 2.0.0-rc3.

* Mon Aug 20 2018 Simone Caronni - 2:2.0.0-44.rc3

- Update SPEC file.

* Sat Aug 4 2018 Mike DePaulo - 2:2.0.0-43.20180801.rc3

- Update to 2.0.0-rc3

* Fri Jul 13 2018 Fedora Release Engineering - 2:2.0.0-42.20180405gita9ecd6a

- Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild

[ 1 ] Bug #1635839 - [abrt] vinagre: init_freerdp(): vinagre killed by SIGSEGV

https://bugzilla.redhat.com/show_bug.cgi?id=1635839

[ 2 ] Bug #1655205 - [abrt] vinagre: init_freerdp(): vinagre killed by SIGSEGV

https://bugzilla.redhat.com/show_bug.cgi?id=1655205

[ 3 ] Bug #1677320 - Cannot connect to xrdp server

https://bugzilla.redhat.com/show_bug.cgi?id=1677320

[ 4 ] Bug #1684154 - CVE-2018-8786 freerdp: Integer truncation leading to heap-based buffer overflow in update_read_bitmap_update() function [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1684154

[ 5 ] Bug #1661642 - CVE-2018-1000852 freerdp: out of bounds read in drdynvc_process_capability_request [fedora-28]

https://bugzilla.redhat.com/show_bug.cgi?id=1661642

[ 6 ] Bug #1665682 - [abrt] remmina: poll_for_event(): remmina killed by SIGABRT

https://bugzilla.redhat.com/show_bug.cgi?id=1665682

[ 7 ] Bug #1660515 - Remmina NX plugin no longer works

https://bugzilla.redhat.com/show_bug.cgi?id=1660515

[ 8 ] Bug #1667632 - remmina-1.3.3 is available

https://bugzilla.redhat.com/show_bug.cgi?id=1667632

su -c 'dnf upgrade --advisory FEDORA-2019-b2d986c3e9' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 28
Version: 2.0.0
Release: 49.20190304git435872b.fc28
Summary: Free implementation of the Remote Desktop Protocol (RDP)

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here