<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 22:23:07 +0000</lastBuildDate>
    <item>
      <title>ALSA-2020:4647 — Moderate: freerdp and vinagre security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2020:4647</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: freerdp-devel, AlmaLinux:8: vinagre&lt;/p&gt;
&lt;p&gt;FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. The xfreerdp client can connect to RDP servers such as Microsoft Windows machines, xrdp, and VirtualBox.&lt;/p&gt;
&lt;p&gt;The vinagre packages provide the Vinagre remote desktop viewer for the GNOME desktop.&lt;/p&gt;
&lt;p&gt;The following packages have been upgraded to a later upstream version: freerdp (2.1.1). (BZ#1834287)&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* freerdp: Out of bound read in cliprdr_server_receive_capabilities (CVE-2020-11018)&lt;/p&gt;
&lt;p&gt;* freerdp: Out of bound read/write in usb redirection channel (CVE-2020-11039)&lt;/p&gt;
&lt;p&gt;* freerdp: out-of-bounds read in update_read_icon_info function (CVE-2020-11042)&lt;/p&gt;
&lt;p&gt;* freerdp: out-of-bounds read in autodetect_recv_bandwidth_measure_results function (CVE-2020-11047)&lt;/p&gt;
&lt;p&gt;* freerdp: Out-of-bounds read in ntlm_read_ChallengeMessage in winpr/libwinpr/sspi/NTLM/ntlm_message.c. (CVE-2020-13396)&lt;/p&gt;
&lt;p&gt;* freerdp: Out-of-bounds read in security_fips_decrypt in libfreerdp/core/security.c (CVE-2020-13397)&lt;/p&gt;
&lt;p&gt;* freerdp: Out of bound read in update_recv could result in a crash (CVE-2020-11019)&lt;/p&gt;
&lt;p&gt;* freerdp: Integer overflow in VIDEO channel (CVE-2020-11038)&lt;/p&gt;
&lt;p&gt;* freerdp: Out of bound access in clear_decompress_subcode_rlex (CVE-2020-11040)&lt;/p&gt;
&lt;p&gt;* freerdp: Unchecked read of array offset in rdpsnd_recv_wave2_pdu (CVE-2020-11041)&lt;/p&gt;
&lt;p&gt;* freerdp: out of bound read in rfx_process_message_tileset (CVE-2020-11043)&lt;/p&gt;
&lt;p&gt;* freerdp: double free in update_read_cache_bitmap_v3_order function (CVE-2020-11044)&lt;/p&gt;
&lt;p&gt;* freerdp: out of bound…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: freerdp-devel, AlmaLinux:8: vinagre&lt;/p&gt;
&lt;p&gt;FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. The xfreerdp client can connect to RDP servers such as Microsoft Windows machines, xrdp, and VirtualBox.&lt;/p&gt;
&lt;p&gt;The vinagre packages provide the Vinagre remote desktop viewer for the GNOME desktop.&lt;/p&gt;
&lt;p&gt;The following packages have been upgraded to a later upstream version: freerdp (2.1.1). (BZ#1834287)&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* freerdp: Out of bound read in cliprdr_server_receive_capabilities (CVE-2020-11018)&lt;/p&gt;
&lt;p&gt;* freerdp: Out of bound read/write in usb redirection channel (CVE-2020-11039)&lt;/p&gt;
&lt;p&gt;* freerdp: out-of-bounds read in update_read_icon_info function (CVE-2020-11042)&lt;/p&gt;
&lt;p&gt;* freerdp: out-of-bounds read in autodetect_recv_bandwidth_measure_results function (CVE-2020-11047)&lt;/p&gt;
&lt;p&gt;* freerdp: Out-of-bounds read in ntlm_read_ChallengeMessage in winpr/libwinpr/sspi/NTLM/ntlm_message.c. (CVE-2020-13396)&lt;/p&gt;
&lt;p&gt;* freerdp: Out-of-bounds read in security_fips_decrypt in libfreerdp/core/security.c (CVE-2020-13397)&lt;/p&gt;
&lt;p&gt;* freerdp: Out of bound read in update_recv could result in a crash (CVE-2020-11019)&lt;/p&gt;
&lt;p&gt;* freerdp: Integer overflow in VIDEO channel (CVE-2020-11038)&lt;/p&gt;
&lt;p&gt;* freerdp: Out of bound access in clear_decompress_subcode_rlex (CVE-2020-11040)&lt;/p&gt;
&lt;p&gt;* freerdp: Unchecked read of array offset in rdpsnd_recv_wave2_pdu (CVE-2020-11041)&lt;/p&gt;
&lt;p&gt;* freerdp: out of bound read in rfx_process_message_tileset (CVE-2020-11043)&lt;/p&gt;
&lt;p&gt;* freerdp: double free in update_read_cache_bitmap_v3_order function (CVE-2020-11044)&lt;/p&gt;
&lt;p&gt;* freerdp: out of bound…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2020:4647</guid>
    </item>
    <item>
      <title>bdu:2020-02587</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2020-02587</link>
      <description>bdu:2020-02587</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2020-02587</guid>
    </item>
    <item>
      <title>cnvd-2020-31431</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2020-31431</link>
      <description>cnvd-2020-31431</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2020-31431</guid>
    </item>
    <item>
      <title>EUVD-2026-40355</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-40355</link>
      <description>EUVD-2026-40355</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-40355</guid>
    </item>
    <item>
      <title>fkie_cve-2020-11038</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-11038</link>
      <description>&lt;p&gt;In FreeRDP less than or equal to 2.0.0, an Integer Overflow to Buffer Overflow exists. When using /video redirection, a manipulated server can instruct the client to allocate a buffer with a smaller size than requested due to an integer overflow in size calculation. With later messages, the server can manipulate the client to write data out of bound to the previously allocated buffer. This has been patched in 2.1.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In FreeRDP less than or equal to 2.0.0, an Integer Overflow to Buffer Overflow exists. When using /video redirection, a manipulated server can instruct the client to allocate a buffer with a smaller size than requested due to an integer overflow in size calculation. With later messages, the server can manipulate the client to write data out of bound to the previously allocated buffer. This has been patched in 2.1.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-11038</guid>
    </item>
    <item>
      <title>gsd-2020-11038</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-11038</link>
      <description>gsd-2020-11038</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-11038</guid>
    </item>
    <item>
      <title>openSUSE-SU-2020:1090-1 — Security update for freerdp</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2020:1090-1</link>
      <description>&lt;p&gt;Security update for freerdp&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for freerdp&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2020:1090-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2020:2032-1 — Security update for freerdp</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2020:2032-1</link>
      <description>&lt;p&gt;Security update for freerdp&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for freerdp&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2020:2032-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2020-11038</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-11038</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: freerdp2, Ubuntu:20.04:LTS: freerdp2&lt;/p&gt;
&lt;p&gt;In FreeRDP less than or equal to 2.0.0, an Integer Overflow to Buffer Overflow exists. When using /video redirection, a manipulated server can instruct the client to allocate a buffer with a smaller size than requested due to an integer overflow in size calculation. With later messages, the server can manipulate the client to write data out of bound to the previously allocated buffer. This has been patched in 2.1.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: freerdp2, Ubuntu:20.04:LTS: freerdp2&lt;/p&gt;
&lt;p&gt;In FreeRDP less than or equal to 2.0.0, an Integer Overflow to Buffer Overflow exists. When using /video redirection, a manipulated server can instruct the client to allocate a buffer with a smaller size than requested due to an integer overflow in size calculation. With later messages, the server can manipulate the client to write data out of bound to the previously allocated buffer. This has been patched in 2.1.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-11038</guid>
    </item>
  </channel>
</rss>
