Eyal Itkin discovered FreeRDP incorrectly handled certain stream encodings. A malicious server could use this issue to cause FreeRDP to crash, resulting in a denial of service, or possibly execute arbitrary code (CVE-2018-8784, CVE-2018-8785). . MGASA-2019-0012 - Updated freerdp packages fix security vulnerabilities Publication date: 05 Jan 2019 URL: https://advisories.mageia.org/MGASA-2019-0012.html Type: security Affected Mageia releases: 6 CVE: CVE-2018-8784, CVE-2018-8785, CVE-2018-8786, CVE-2018-8787, CVE-2018-8788, CVE-2018-8789 Eyal Itkin discovered FreeRDP incorrectly handled certain stream encodings. A malicious server could use this issue to cause FreeRDP to crash, resulting in a denial of service, or possibly execute arbitrary code (CVE-2018-8784, CVE-2018-8785). Eyal Itkin discovered FreeRDP incorrectly handled bitmaps. A malicious server could use this issue to cause FreeRDP to crash, resulting in a denial of service, or possibly execute arbitrary code (CVE-2018-8786, CVE-2018-8787). Eyal Itkin discovered FreeRDP incorrectly handled certain stream encodings. A malicious server could use this issue to cause FreeRDP to crash, resulting in a denial of service, or possibly execute arbitrary code (CVE-2018-8788). Eyal Itkin discovered FreeRDP incorrectly handled NTLM authentication. A malicious server could use this issue to cause FreeRDP to crash, resulting in a denial of service, or possibly execute arbitrary code (CVE-2018-8789). References: - https://bugs.mageia.org/show_bug.cgi?id=24074 - https://ubuntu.com/security/notices/USN-3845-1 - https://www.cve.org/CVERecord?id=CVE-2018-8784 - https://www.cve.org/CVERecord?id=CVE-2018-8785 - https://www.cve.org/CVERecord?id=CVE-2018-8786 - https://www.cve.org/CVERecord?id=CVE-2018-8787 - https://www.cve.org/CVERecord?id=CVE-2018-8788 - https://www.cve.org/CVERecord?id=CVE-2018-8789 SRPMS: - 6/core/freerdp-2.0.0-0.rc4.1.mga6 . Mageia 2019-0013 addresses critical vulnerabilities in Samba, preventing possible data breachesand unauthorized access risks.. FreeRDP Security Update, Mageia Advisory, Denial of Service, Code Execution Vulnerabilities. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.