Allele Security Alert
ASA-2019-00066
Identifier(s)
ASA-2019-00066, CVE-2018-8784
Title
Heap-based buffer overflow in function zgfx_decompress_segment()
Vendor(s)
FreeRDP project
Product(s)
FreeRDP
Affected version(s)
FreeRDP prior to version 2.0.0-rc4
Fixed version(s)
FreeRDP 2.0.0-rc4
Proof of concept
Unknown
Description
FreeRDP prior to version 2.0.0-rc4 contains a heap-based buffer overflow in function zgfx_decompress_segment() that results in a memory corruption and probably even a remote code execution.
Technical details
Unknown
Credits
Eyal Itkin (Checkpoint Research)
Reference(s)
2.0.0-rc4 released
http://www.freerdp.com/2018/11/20/2_0_0_rc4-released
Reverse RDP Attack: Code Execution on RDP Clients
https://research.checkpoint.com/reverse-rdp-attack-code-execution-on-rdp-clients/
CVE-2018-8784
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-8784
CVE-2018-8784
https://nvd.nist.gov/vuln/detail/CVE-2018-8784
If there is any error in this alert or you wish a comprehensive analysis, let us know.
Last modified: February 11, 2019