{"id":"openSUSE-SU-2019:2135-1","summary":"Security update for rdesktop","details":"This update for rdesktop fixes the following issues:\n\nrdesktop was updated to 1.8.6:\n\n* Fix protocol code handling new licenses\n\nrdesktop was updated to 1.8.5:\n\n* Add bounds checking to protocol handling in order to fix many\n  security problems when communicating with a malicious server.\n\nrdesktop was updated to 1.8.4 (fix for boo#1121448):\n\n* Add rdp_protocol_error function that is used in several fixes\n* Refactor of process_bitmap_updates\n* Fix possible integer overflow in s_check_rem() on 32bit arch\n* Fix memory corruption in process_bitmap_data - CVE-2018-8794\n* Fix remote code execution in process_bitmap_data - CVE-2018-8795\n* Fix remote code execution in process_plane - CVE-2018-8797\n* Fix Denial of Service in mcs_recv_connect_response - CVE-2018-20175\n* Fix Denial of Service in mcs_parse_domain_params - CVE-2018-20175\n* Fix Denial of Service in sec_parse_crypt_info - CVE-2018-20176\n* Fix Denial of Service in sec_recv - CVE-2018-20176\n* Fix minor information leak in rdpdr_process - CVE-2018-8791\n* Fix Denial of Service in cssp_read_tsrequest - CVE-2018-8792\n* Fix remote code execution in cssp_read_tsrequest - CVE-2018-8793\n* Fix Denial of Service in process_bitmap_data - CVE-2018-8796\n* Fix minor information leak in rdpsnd_process_ping - CVE-2018-8798\n* Fix Denial of Service in process_secondary_order - CVE-2018-8799\n* Fix remote code execution in in ui_clip_handle_data - CVE-2018-8800\n* Fix major information leak in ui_clip_handle_data - CVE-2018-20174\n* Fix memory corruption in rdp_in_unistr - CVE-2018-20177\n* Fix Denial of Service in process_demand_active - CVE-2018-20178\n* Fix remote code execution in lspci_process - CVE-2018-20179\n* Fix remote code execution in rdpsnddbg_process - CVE-2018-20180\n* Fix remote code execution in seamless_process - CVE-2018-20181\n* Fix remote code execution in seamless_process_line - CVE-2018-20182\n* Fix building against OpenSSL 1.1\n- remove obsolete patches\n* rdesktop-Fix-OpenSSL-1.1-compability-issues.patch\n* rdesktop-Fix-crash-in-rdssl_cert_to_rkey.patch\n\n- update changes file\n* add missing info about bugzilla 1121448\n\n- Added rdesktop-Fix-decryption.patch\nPatch from https://github.com/rdesktop/rdesktop/pull/334 to fix\nconnections to VirtualBox.\n\n- update to 1.8.6\n* Fix protocol code handling new licenses\n\n- update to 1.8.5\n* Add bounds checking to protocol handling in order to fix many\nsecurity problems when communicating with a malicious server.\n\n- Trim redundant wording from description.\n- Use %make_install.\n\n- update to 1.8.4 (fix for boo#1121448)\n* Add rdp_protocol_error function that is used in several fixes\n* Refactor of process_bitmap_updates\n* Fix possible integer overflow in s_check_rem() on 32bit arch\n* Fix memory corruption in process_bitmap_data - CVE-2018-8794\n* Fix remote code execution in process_bitmap_data - CVE-2018-8795\n* Fix remote code execution in process_plane - CVE-2018-8797\n* Fix Denial of Service in mcs_recv_connect_response - CVE-2018-20175\n* Fix Denial of Service in mcs_parse_domain_params - CVE-2018-20175\n* Fix Denial of Service in sec_parse_crypt_info - CVE-2018-20176\n* Fix Denial of Service in sec_recv - CVE-2018-20176\n* Fix minor information leak in rdpdr_process - CVE-2018-8791\n* Fix Denial of Service in cssp_read_tsrequest - CVE-2018-8792\n* Fix remote code execution in cssp_read_tsrequest - CVE-2018-8793\n* Fix Denial of Service in process_bitmap_data - CVE-2018-8796\n* Fix minor information leak in rdpsnd_process_ping - CVE-2018-8798\n* Fix Denial of Service in process_secondary_order - CVE-2018-8799\n* Fix remote code execution in in ui_clip_handle_data - CVE-2018-8800\n* Fix major information leak in ui_clip_handle_data - CVE-2018-20174\n* Fix memory corruption in rdp_in_unistr - CVE-2018-20177\n* Fix Denial of Service in process_demand_active - CVE-2018-20178\n* Fix remote code execution in lspci_process - CVE-2018-20179\n* Fix remote code execution in rdpsnddbg_process - CVE-2018-20180\n* Fix remote code execution in seamless_process - CVE-2018-20181\n* Fix remote code execution in seamless_process_line - CVE-2018-20182\n* Fix building against OpenSSL 1.1\n","modified":"2026-03-11T07:32:14.093962Z","published":"2019-09-14T16:17:10Z","related":["CVE-2018-20174","CVE-2018-20175","CVE-2018-20176","CVE-2018-20177","CVE-2018-20178","CVE-2018-20179","CVE-2018-20180","CVE-2018-20181","CVE-2018-20182","CVE-2018-8791","CVE-2018-8792","CVE-2018-8793","CVE-2018-8794","CVE-2018-8795","CVE-2018-8796","CVE-2018-8797","CVE-2018-8798","CVE-2018-8799","CVE-2018-8800"],"upstream":["CVE-2018-20174","CVE-2018-20175","CVE-2018-20176","CVE-2018-20177","CVE-2018-20178","CVE-2018-20179","CVE-2018-20180","CVE-2018-20181","CVE-2018-20182","CVE-2018-8791","CVE-2018-8792","CVE-2018-8793","CVE-2018-8794","CVE-2018-8795","CVE-2018-8796","CVE-2018-8797","CVE-2018-8798","CVE-2018-8799","CVE-2018-8800"],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/5MCVZLNEOZHBW55VIVPPCJCYS3FNB6ZZ/#5MCVZLNEOZHBW55VIVPPCJCYS3FNB6ZZ"},{"type":"REPORT","url":"https://bugzilla.suse.com/1121448"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-20174"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-20175"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-20176"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-20177"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-20178"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-20179"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-20180"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-20181"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-20182"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-8791"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-8792"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-8793"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-8794"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-8795"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-8796"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-8797"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-8798"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-8799"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-8800"}],"affected":[{"package":{"name":"rdesktop","ecosystem":"SUSE:Package Hub 15 SP1","purl":"pkg:rpm/suse/rdesktop&distro=SUSE%20Package%20Hub%2015%20SP1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.8.6-bp151.2.3.1"}]}],"ecosystem_specific":{"binaries":[{"rdesktop":"1.8.6-bp151.2.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2019:2135-1.json"}},{"package":{"name":"rdesktop","ecosystem":"openSUSE:Leap 15.1","purl":"pkg:rpm/opensuse/rdesktop&distro=openSUSE%20Leap%2015.1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.8.6-bp151.2.3.1"}]}],"ecosystem_specific":{"binaries":[{"rdesktop":"1.8.6-bp151.2.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2019:2135-1.json"}}],"schema_version":"1.7.5"}