ALAS2-2019-1191


Amazon Linux 2 Security Advisory: ALAS-2019-1191
Advisory Release Date: 2019-04-04 21:55 Pacific
Advisory Updated Date: 2019-04-17 17:01 Pacific
Severity: Important

Issue Overview:

FreeRDP prior to version 2.0.0-rc4 contains an Out-Of-Bounds Write of up to 4 bytes in function nsc_rle_decode() that results in a memory corruption and possibly even a remote code execution.(CVE-2018-8788)

FreeRDP prior to version 2.0.0-rc4 contains an Integer Overflow that leads to a Heap-Based Buffer Overflow in function gdi_Bitmap_Decompress() and results in a memory corruption and probably even a remote code execution.(CVE-2018-8787)

FreeRDP prior to version 2.0.0-rc4 contains an Integer Truncation that leads to a Heap-Based Buffer Overflow in function update_read_bitmap_update() and results in a memory corruption and probably even a remote code execution.(CVE-2018-8786)


Affected Packages:

freerdp


Note:

This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.


Issue Correction:
Run yum update freerdp to update your system.

New Packages:
aarch64:
    freerdp-1.0.2-15.amzn2.0.1.aarch64
    freerdp-libs-1.0.2-15.amzn2.0.1.aarch64
    freerdp-plugins-1.0.2-15.amzn2.0.1.aarch64
    freerdp-devel-1.0.2-15.amzn2.0.1.aarch64
    freerdp-debuginfo-1.0.2-15.amzn2.0.1.aarch64

i686:
    freerdp-1.0.2-15.amzn2.0.1.i686
    freerdp-libs-1.0.2-15.amzn2.0.1.i686
    freerdp-plugins-1.0.2-15.amzn2.0.1.i686
    freerdp-devel-1.0.2-15.amzn2.0.1.i686
    freerdp-debuginfo-1.0.2-15.amzn2.0.1.i686

src:
    freerdp-1.0.2-15.amzn2.0.1.src

x86_64:
    freerdp-1.0.2-15.amzn2.0.1.x86_64
    freerdp-libs-1.0.2-15.amzn2.0.1.x86_64
    freerdp-plugins-1.0.2-15.amzn2.0.1.x86_64
    freerdp-devel-1.0.2-15.amzn2.0.1.x86_64
    freerdp-debuginfo-1.0.2-15.amzn2.0.1.x86_64