Skip to main content

Out-of-bounds Read

CVE-2020-4030

Severity Low
Score 3.5/10

Summary

In FreeRDP before version 2.1.2, there is an out of bounds read in TrioParse. Logging might bypass string length checks due to an integer overflow. This is fixed in version 2.1.2.

  • HIGH
  • NETWORK
  • LOW
  • CHANGED
  • NONE
  • LOW
  • NONE
  • NONE

CWE-125 - Out-of-Bounds Read

Out-of-bounds read is a vulnerability that allows access to memory beyond the authorized accessible location. Such a vulnerability compromises the confidentiality of the trusted environment in the application and enables an attacker to launch further attacks by leveraging the exposed information.

References

Advisory Timeline

  • Published