• FreeRDP vulnerabilities

    From bugz_ubuntu@21:4/110 to Ubuntu Users on Thursday, June 04, 2020 12:10:02
    freerdp vulnerabilities

    A security issue affects these releases of Ubuntu and its
    derivatives:

    * Ubuntu 16.04 LTS

    Summary

    Several security issues were fixed in FreeRDP.

    Software Description

    * freerdp - RDP client for Windows Terminal Services

    Details

    It was discovered that FreeRDP incorrectly handled certain memory
    operations. A remote attacker could use this issue to cause
    FreeRDP to crash, resulting in a denial of service, or possibly
    execute arbitrary code.

    Update instructions

    The problem can be corrected by updating your system to the
    following package versions:

    Ubuntu 16.04 LTS
    libfreerdp-client1.1 -
    1.1.0~git20140921.1.440916e+dfsg1-5ubuntu1.4
    libfreerdp-common1.1.0 -
    1.1.0~git20140921.1.440916e+dfsg1-5ubuntu1.4
    libfreerdp-core1.1 -
    1.1.0~git20140921.1.440916e+dfsg1-5ubuntu1.4

    To update your system, please follow these instructions:
    https://wiki.ubuntu.com/Security/Upgrades.

    In general, a standard system update will make all the necessary
    changes.

    References

    * CVE-2020-11042
    * CVE-2020-11045
    * CVE-2020-11046
    * CVE-2020-11048
    * CVE-2020-11049
    * CVE-2020-11058
    * CVE-2020-11521
    * CVE-2020-11522
    * CVE-2020-11523
    * CVE-2020-11525
    * CVE-2020-11526
    * CVE-2020-13396
    * CVE-2020-13397
    * CVE-2020-13398

    --- Mystic BBS v1.12 A45 (Linux/64)
    * Origin: BZ&BZ BBS (21:4/110)
  • From bugz_ubuntu@21:4/110 to Ubuntu Users on Tuesday, September 01, 2020 12:10:02
    freerdp2 vulnerabilities

    A security issue affects these releases of Ubuntu and its
    derivatives:

    * Ubuntu 20.04 LTS
    * Ubuntu 18.04 LTS

    Summary

    Several security issues were fixed in FreeRDP.

    Software Description

    * freerdp2 - RDP client for Windows Terminal Services

    Details

    It was discovered that FreeRDP incorrectly handled certain memory
    operations. A remote attacker could use this issue to cause
    FreeRDP to crash, resulting in a denial of service, or possibly
    execute arbitrary code.

    Update instructions

    The problem can be corrected by updating your system to the
    following package versions:

    Ubuntu 20.04 LTS
    libfreerdp-client2-2 - 2.2.0+dfsg1-0ubuntu0.20.04.1
    libfreerdp-server2-2 - 2.2.0+dfsg1-0ubuntu0.20.04.1
    libfreerdp2-2 - 2.2.0+dfsg1-0ubuntu0.20.04.1

    Ubuntu 18.04 LTS
    libfreerdp-client2-2 - 2.2.0+dfsg1-0ubuntu0.18.04.1
    libfreerdp-server2-2 - 2.2.0+dfsg1-0ubuntu0.18.04.1
    libfreerdp2-2 - 2.2.0+dfsg1-0ubuntu0.18.04.1

    To update your system, please follow these instructions:
    https://wiki.ubuntu.com/Security/Upgrades.

    This update uses a new upstream release, which includes additional
    bug fixes. In general, a standard system update will make all the
    necessary changes.

    References

    * CVE-2020-11095
    * CVE-2020-11096
    * CVE-2020-11097
    * CVE-2020-11098
    * CVE-2020-11099
    * CVE-2020-15103
    * CVE-2020-4030
    * CVE-2020-4031
    * CVE-2020-4032
    * CVE-2020-4033

    --- Mystic BBS v1.12 A46 (Linux/64)
    * Origin: BZ&BZ BBS (21:4/110)