rdesktop versions up to and including v1.8.3 contain a buffer overflow over the global variables in function seamless_process_line() that results in a memory corruption and probably even a remote code execution.
Tag: rdesktop
ASA-2019-00064 – rdesktop: Integer underflow that leads to a heap-based buffer overflow in function seamless_process()
rdesktop versions up to and including v1.8.3 contain an integer underflow that leads to a heap-based buffer overflow in function seamless_process() and results in a memory corruption and probably even a remote code execution.
ASA-2019-00063 – rdesktop: Integer underflow that leads to a heap-based buffer overflow in function rdpsnddbg_process()
rdesktop versions up to and including v1.8.3 contain an integer underflow that leads to a heap-based buffer overflow in function rdpsnddbg_process() and results in a memory corruption and probably even a remote code execution.
ASA-2019-00062 – rdesktop: Integer underflow that leads to a heap-based buffer overflow in function lspci_process()
rdesktop versions up to and including v1.8.3 contain an integer underflow that leads to a heap-based buffer overflow in function lspci_process() and results in a memory corruption and probably even a remote code execution.
ASA-2019-00061 – rdesktop: Out-of-bounds read in function process_demand_active()
rdesktop versions up to and including v1.8.3 contain an out-of-bounds read in function process_demand_active() that results in a denial of service (segfault).
ASA-2019-00060 – rdesktop: Integer overflow that leads to a heap-based buffer overflow in function rdp_in_unistr()
rdesktop versions up to and including v1.8.3 contain an integer overflow that leads to a heap-based buffer overflow in function rdp_in_unistr() and results in a memory corruption and possibly even a remote code execution.
ASA-2019-00059 – rdesktop: Several out-of-bounds reads in file secure.c
rdesktop versions up to and including v1.8.3 contains several out-of-bounds reads in file secure.c that result in a denial of service (segfault).
ASA-2019-00058 – rdesktop: Several integer signedness errors that leads to out-of-bounds reads in file mcs.c
rdesktop versions up to and including v1.8.3 contains several integer signedness errors that leads to out-of-bounds reads in file mcs.c and result in a denial of service (segfault).