CVE-2019-17177
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
04/10/2019
Last modified:
21/07/2021
Description
libfreerdp/codec/region.c in FreeRDP through 1.1.x and 2.x through 2.0.0-rc4 has memory leaks because a supplied realloc pointer (i.e., the first argument to realloc) is also used for a realloc return value.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:* | 1.0.2 (including) | |
| cpe:2.3:a:freerdp:freerdp:1.1.0:beta:*:*:*:*:*:* | ||
| cpe:2.3:a:freerdp:freerdp:1.1.0:beta1:*:*:*:*:*:* | ||
| cpe:2.3:a:freerdp:freerdp:2.0.0:beta1:*:*:*:*:*:* | ||
| cpe:2.3:a:freerdp:freerdp:2.0.0:rc0:*:*:*:*:*:* | ||
| cpe:2.3:a:freerdp:freerdp:2.0.0:rc1:*:*:*:*:*:* | ||
| cpe:2.3:a:freerdp:freerdp:2.0.0:rc2:*:*:*:*:*:* | ||
| cpe:2.3:a:freerdp:freerdp:2.0.0:rc3:*:*:*:*:*:* | ||
| cpe:2.3:a:freerdp:freerdp:2.0.0:rc4:*:*:*:*:*:* | ||
| cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:* | ||
| cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00005.html
- https://github.com/FreeRDP/FreeRDP/commit/9fee4ae076b1ec97b97efb79ece08d1dab4df29a
- https://github.com/FreeRDP/FreeRDP/issues/5645
- https://security.gentoo.org/glsa/202005-07
- https://usn.ubuntu.com/4379-1/



