Name | CVE-2017-2837 |
Description | An exploitable denial of service vulnerability exists within the handling of security data in FreeRDP 2.0.0-beta1+android11. A specially crafted challenge packet can cause the program termination leading to a denial of service condition. An attacker can compromise the server or use man in the middle to trigger this vulnerability. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DLA-1095-1, DSA-3923-1 |
Debian Bugs | 869880 |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
freerdp | source | wheezy | 1.0.1-1.1+deb7u4 | DLA-1095-1 | ||
freerdp | source | jessie | 1.1.0~git20140921.1.440916e+dfsg1-4+deb8u1 | DSA-3923-1 | ||
freerdp | source | stretch | 1.1.0~git20140921.1.440916e+dfsg1-13+deb9u1 | DSA-3923-1 | ||
freerdp | source | (unstable) | 1.1.0~git20140921.1.440916e+dfsg1-14 | 869880 |
https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0339
http://blog.talosintelligence.com/2017/07/vulnerbility-spotlight-freerdp-multiple.html
https://github.com/FreeRDP/FreeRDP/commit/03ab68318966c3a22935a02838daaea7b7fbe96c (1.1)