Allele Security Alert
ASA-2019-00053
Identifier(s)
ASA-2019-00053, CVE-2018-8797
Title
Heap-based buffer overflow in function process_plane()
Vendor(s)
rdesktop team
Product(s)
rdesktop
Affected version(s)
rdesktop versions up to and including v1.8.3
Fixed version(s)
rdesktop v1.8.4
Proof of concept
Unknown
Description
rdesktop versions up to and including v1.8.3 contain a heap-based buffer overflow in function process_plane() that results in a memory corruption and probably even a remote code execution.
Technical details
Unknown
Credits
Eyal Itkin (Checkpoint Research)
Reference(s)
Reverse RDP Attack: Code Execution on RDP Clients
https://research.checkpoint.com/reverse-rdp-attack-code-execution-on-rdp-clients/
Updated ChangeLog and bumped version to 1.8.4
https://github.com/rdesktop/rdesktop/commit/34b8a18fe5d4de795851defe34b3ad3e1f43532b
CVE-2018-8797
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-8797
CVE-2018-8797
https://nvd.nist.gov/vuln/detail/CVE-2018-8797
If there is any error in this alert or you wish a comprehensive analysis, let us know.
Last modified: February 11, 2019