ASA-2019-00056 – rdesktop: Heap-based buffer overflow in function ui_clip_handle_data()


Para a versão em português deste alerta, clique aqui.

Allele Security Alert

ASA-2019-00056

Identifier(s)

ASA-2019-00056, CVE-2018-8800

Title

Heap-based buffer overflow in function ui_clip_handle_data()

Vendor(s)

rdesktop team

Product(s)

rdesktop

Affected version(s)

rdesktop versions up to and including v1.8.3

Fixed version(s)

rdesktop v1.8.4

Proof of concept

Unknown

Description

rdesktop versions up to and including v1.8.3 contain a heap-based buffer overflow in function ui_clip_handle_data() that results in a memory corruption and probably even a remote code execution.

Technical details

Unknown

Credits

Eyal Itkin (Checkpoint Research)

Reference(s)

Reverse RDP Attack: Code Execution on RDP Clients
https://research.checkpoint.com/reverse-rdp-attack-code-execution-on-rdp-clients/

Updated ChangeLog and bumped version to 1.8.4
https://github.com/rdesktop/rdesktop/commit/34b8a18fe5d4de795851defe34b3ad3e1f43532b

CVE-2018-8800
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-8800

CVE-2018-8800
https://nvd.nist.gov/vuln/detail/CVE-2018-8800

If there is any error in this alert or you wish a comprehensive analysis, let us know.

Last modified: February 11, 2019