CVE-2017-2834 PUBLISHED

An exploitable code execution vulnerability exists in the authentication functionality of FreeRDP 2.0.0-beta1+android11. A specially crafted server response can cause an out-of-bounds write resulting in an exploitable condition. An attacker can compromise the server or use a man in the middle attack to trigger this vulnerability.

EPSS 1.07% · 77.6th percentile

Risk Scores

EPSS Score
1.07%
77.6th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSfreerdp0, 1.1.0~git20140921.1.440916e+dfsg1-5ubuntu1

Timeline

References

Open in Interactive Console →