VDB

ALINUX2-SA-2019%3A0102

ALINUX2-SA-2019%3A0102 PUBLISHED CVSS 4.300000190734863 MEDIUM

Package updates are available for Alibaba Cloud Linux 2.1903 that fix the following vulnerabilities: CVE-2018-1000852: FreeRDP FreeRDP 2.0.0-rc3 released version before commit 205c612820dac644d665b5bb1cdf437dc5ca01e3 contains a Other/Unknown vulnerability in channels/drdynvc/client/drdynvc_main.c, drdynvc_process_capability_request that can result in The RDP server can read the client's memory.. This attack appear to be exploitable via RDPClient must connect the rdp server with echo option. This vulnerability appears to have been fixed in after commit 205c612820dac644d665b5bb1cdf437dc5ca01e3.

Risk Scores

CVSS 3.0
4.300000190734863
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

Affected Products

VendorProductVersions
Alibaba Cloudvinagre
Alibaba Cloudfreerdp

Timeline

  • Oct 22, 2019 CVE Published
  • Oct 22, 2019 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›