Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Fedora 32: FEDORA-2020-8d5f86e29a Critical: freerdp Security Fixes

fedora
Calendar Grey July 30, 2020
Dist Fedora Esm H88
Major Fedora update for freerdp addresses multiple vulnerabilities and bugs. It is recommended to upgrade for enhanced security.
Bugfix and CVE release.

Summary

The xfreerdp & wlfreerdp Remote Desktop Protocol (RDP) clients from the FreeRDP

project.

xfreerdp & wlfreerdp can connect to RDP servers such as Microsoft Windows

machines, xrdp and VirtualBox.

Bugfix and CVE release.

* Thu Jul 23 2020 Simone Caronni - 2:2.2.0-1

- Update to 2.2.0.

[ 1 ] Bug #1854844 - CVE-2020-11098 freerdp: out-of-bound read in glyph_cache_put [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1854844

[ 2 ] Bug #1854848 - CVE-2020-11096 freerdp: out-of-bound read in update_read_cache_bitmap_v3_order [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1854848

[ 3 ] Bug #1854852 - CVE-2020-11095 freerdp: out of bound reads resulting in accessing memory location outside of static array PRIMARY_DRAWING_ORDER_FIELD_BYTES. [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1854852

[ 4 ] Bug #1854872 - CVE-2020-4032 freerdp: integer casting vulnerability in update_recv_secondary_order [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1854872

[ 5 ] Bug #1854886 - CVE-2020-4033 freerdp: out-of-bounds read in RLEDECOMPRESS [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1854886

[ 6 ] Bug #1854890 - CVE-2020-4031 freerdp: use-after-free in gdi_SelectObject [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1854890

[ 7 ] Bug #1854896 - CVE-2020-4030 freerdp: out of bounds read in TrioParse [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1854896

[ 8 ] Bug #1854900 - CVE-2020-11099 freerdp: out of bounds read in license_read_new_or_upgrade_license_packet [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1854900

[ 9 ] Bug #1854913 - CVE-2020-11097 freerdp: out of bounds read in PRIMARY_DRAWING_ORDER_FIELD_BYTES [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1854913

[ 10 ] Bug #1855226 - Disconnected on Windows 2008 R2 after update to 2.1.2-1

https://bugzilla.redhat.com/show_bug.cgi?id=1855226

[ 11 ] Bug #1858483 - remmina - can not connect to Windows Server 2008 after last update

https://bugzilla.redhat.com/show_bug.cgi?id=1858483

[ 12 ] Bug #1858910 - CVE-2020-15103 freerdp: integer overflow due to missing input sanitation in rdpegfx channel [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1858910

[ 13 ] Bug #1859579 - Freerdp version 2.2.0 fixes disconnection issue, please update

https://bugzilla.redhat.com/show_bug.cgi?id=1859579

su -c 'dnf upgrade --advisory FEDORA-2020-8d5f86e29a' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 32
Version: 2.2.0
Release: 1.fc32
Summary: Free implementation of the Remote Desktop Protocol (RDP)

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here