CVE-2008-1803

Severity CVSS v4.0:
Pending analysis
Type:
CWE-189 Numeric Errors
Publication date:
12/05/2008
Last modified:
09/04/2025

Description

Integer signedness error in the xrealloc function (rdesktop.c) in RDesktop 1.5.0 allows remote attackers to execute arbitrary code via unknown parameters that trigger a heap-based overflow. NOTE: the role of the channel_process function was not specified by the original researcher.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:rdesktop:rdesktop:1.5.0:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools