Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

RedHat: RHSA-2020-4683 Important: OpenSSL Security Patch Released

red hat
Calendar Grey November 3, 2020
Dist Redhat Esm H88
Recent security patches for Freerdp and Vinagre on Red Hat Enterprise Linux 8 address multiple vulnerabilities, offering detailed insights on the fixes and impacts
An update for freerdp and vinagre is now available for Red Hat Enterprise Linux 8

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Summary

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. The xfreerdp client can connect to RDP servers such as Microsoft Windows machines, xrdp, and VirtualBox.
The vinagre packages provide the Vinagre remote desktop viewer for the GNOME desktop.
The following packages have been upgraded to a later upstream version: freerdp (2.1.1). (BZ#1834287)
Security Fix(es):
* freerdp: Out of bound read in cliprdr_server_receive_capabilities (CVE-2020-11018)
* freerdp: Out of bound read/write in usb redirection channel (CVE-2020-11039)
* freerdp: out-of-bounds read in update_read_icon_info function (CVE-2020-11042)
* freerdp: out-of-bounds read in autodetect_recv_bandwidth_measure_results function (CVE-2020-11047)
* freerdp: Out-of-bounds read in ntlm_read_ChallengeMessage in winpr/libwinpr/sspi/NTLM/ntlm_message.c. (CVE-2020-13396)
* freerdp: Out-of-bounds read in security_fips_decrypt in libfreerdp/core/security.c (CVE-2020-13397)
* freerdp: Out of bound read in update_recv could result in a crash (CVE-2020-11019)
* freerdp: Integer overflow in VIDEO channel (CVE-2020-11038)
* freerdp: Out of bound access in clear_decompress_subcode_rlex (CVE-2020-11040)
* freerdp: Unchecked read of array offset in rdpsnd_recv_wave2_pdu (CVE-2020-11041)
* freerdp: out of bound read in rfx_process_message_tileset (CVE-2020-11043)
* freerdp: double free in update_read_cache_bitmap_v3_order function (CVE-2020-11044)
* freerdp: out of bounds read in update_read_bitmap_data function (CVE-2020-11045)
* freerdp: out of bounds seek in update_read_synchronize function could lead out of bounds read (CVE-2020-11046)
* freerdp: out-of-bounds read could result in aborting the session (CVE-2020-11048)
* freerdp: out-of-bound read of client memory that is then passed on to the protocol parser (CVE-2020-11049)
* freerdp: stream out-of-bounds seek in rdp_read_font_capability_set could lead to out-of-bounds read (CVE-2020-11058)
* freerdp: out-of-bounds read in cliprdr_read_format_list function (CVE-2020-11085)
* freerdp: out-of-bounds read in ntlm_read_ntlm_v2_client_challenge function (CVE-2020-11086)
* freerdp: out-of-bounds read in ntlm_read_AuthenticateMessage (CVE-2020-11087)
* freerdp: out-of-bounds read in ntlm_read_NegotiateMessage (CVE-2020-11088)
* freerdp: out-of-bounds read in irp functions (CVE-2020-11089)
* freerdp: out-of-bounds read in gdi.c (CVE-2020-11522)
* freerdp: out-of-bounds read in bitmap.c (CVE-2020-11525)
* freerdp: Stream pointer out of bounds in update_recv_secondary_order could lead out of bounds read later (CVE-2020-11526)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.3 Release Notes linked from the References section.

References

https://access.redhat.com/security/cve/CVE-2020-11018 https://access.redhat.com/security/cve/CVE-2020-11019 https://access.redhat.com/security/cve/CVE-2020-11038 https://access.redhat.com/security/cve/CVE-2020-11039 https://access.redhat.com/security/cve/CVE-2020-11040 https://access.redhat.com/security/cve/CVE-2020-11041 https://access.redhat.com/security/cve/CVE-2020-11042 https://access.redhat.com/security/cve/CVE-2020-11043 https://access.redhat.com/security/cve/CVE-2020-11044 https://access.redhat.com/security/cve/CVE-2020-11045 https://access.redhat.com/security/cve/CVE-2020-11046 https://access.redhat.com/security/cve/CVE-2020-11047 https://access.redhat.com/security/cve/CVE-2020-11048 https://access.redhat.com/security/cve/CVE-2020-11049 https://access.redhat.com/security/cve/CVE-2020-11058 https://access.redhat.com/security/cve/CVE-2020-11085 https://access.redhat.com/security/cve/CVE-2020-11086 https://access.redhat.com/security/cve/CVE-2020-11087 https://access.redhat.com/security/cve/CVE-2020-11088 https://access.redhat.com/security/cve/CVE-2020-11089 https://access.redhat.com/security/cve/CVE-2020-11522 https://access.redhat.com/security/cve/CVE-2020-11525 https://access.redhat.com/security/cve/CVE-2020-11526 Read the Full Advisory

Package List

Red Hat Enterprise Linux AppStream (v. 8):
Source: freerdp-2.1.1-1.el8.src.rpm vinagre-3.22.0-23.el8.src.rpm
aarch64: freerdp-2.1.1-1.el8.aarch64.rpm freerdp-debuginfo-2.1.1-1.el8.aarch64.rpm freerdp-debugsource-2.1.1-1.el8.aarch64.rpm freerdp-libs-2.1.1-1.el8.aarch64.rpm freerdp-libs-debuginfo-2.1.1-1.el8.aarch64.rpm libwinpr-2.1.1-1.el8.aarch64.rpm libwinpr-debuginfo-2.1.1-1.el8.aarch64.rpm libwinpr-devel-2.1.1-1.el8.aarch64.rpm vinagre-3.22.0-23.el8.aarch64.rpm vinagre-debuginfo-3.22.0-23.el8.aarch64.rpm vinagre-debugsource-3.22.0-23.el8.aarch64.rpm
ppc64le: freerdp-2.1.1-1.el8.ppc64le.rpm freerdp-debuginfo-2.1.1-1.el8.ppc64le.rpm freerdp-debugsource-2.1.1-1.el8.ppc64le.rpm freerdp-libs-2.1.1-1.el8.ppc64le.rpm freerdp-libs-debuginfo-2.1.1-1.el8.ppc64le.rpm libwinpr-2.1.1-1.el8.ppc64le.rpm libwinpr-debuginfo-2.1.1-1.el8.ppc64le.rpm libwinpr-devel-2.1.1-1.el8.ppc64le.rpm vinagre-3.22.0-23.el8.ppc64le.rpm vinagre-debuginfo-3.22.0-23.el8.ppc64le.rpm vinagre-debugsource-3.22.0-23.el8.ppc64le.rpm
s390x: freerdp-2.1.1-1.el8.s390x.rpm freerdp-debuginfo-2.1.1-1.el8.s390x.rpm freerdp-debugsource-2.1.1-1.el8.s390x.rpm freerdp-libs-2.1.1-1.el8.s390x.rpm freerdp-libs-debuginfo-2.1.1-1.el8.s390x.rpm libwinpr-2.1.1-1.el8.s390x.rpm libwinpr-debuginfo-2.1.1-1.el8.s390x.rpm

Read the Full Advisory


Severity
important
Lowest
Low
Medium
High
Critical

Advisory ID: RHSA-2020:4647-01
Product: Red Hat Enterprise Linux
Issue date: 2020-11-03

Topic

An update for freerdp and vinagre is now available for Red Hat EnterpriseLinux 8.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.

Relevant Releases Architectures

Red Hat CodeReady Linux Builder (v. 8) - aarch64, ppc64le, s390x, x86_64

Red Hat Enterprise Linux AppStream (v. 8) - aarch64, ppc64le, s390x, x86_64

Bugs Fixed

1761144 - Remove unsupported options from xfreerdp /help

1803054 - SCARD_INSUFFICIENT_BUFFER error when connecting to Windows 10 system

1834287 - Update freerdp to 2.1.1

1835382 - CVE-2020-11042 freerdp: out-of-bounds read in update_read_icon_info function

1835391 - CVE-2020-11044 freerdp: double free in update_read_cache_bitmap_v3_order function

1835399 - CVE-2020-11045 freerdp: out of bounds read in update_read_bitmap_data function

1835403 - CVE-2020-11046 freerdp: out of bounds seek in update_read_synchronize function could lead out of bounds read

1835762 - CVE-2020-11047 freerdp: out-of-bounds read in autodetect_recv_bandwidth_measure_results function

1835766 - CVE-2020-11048 freerdp: out-of-bounds read could result in aborting the session

1835772 - CVE-2020-11049 freerdp: out-of-bound read of client memory that is then passed on to the protocol parser

1835779 - CVE-2020-11058 freerdp: stream out-of-bounds seek in rdp_read_font_capability_set could lead to out-of-bounds read

1836223 - CVE-2020-11522 freerdp: out-of-bounds read in gdi.c

1836239 - CVE-2020-11525 freerdp: out-of-bounds read in bitmap.c

1836247 - CVE-2020-11526 freerdp: Stream pointer out of bounds in update_recv_secondary_order could lead out of bounds read later

1839744 - Rebuild vinagre against new freerdp

Read the Full Advisory

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here