Bug 1116708 (CVE-2018-8784) - VUL-0: CVE-2018-8784: freerdp: Heap-Based Buffer Overflow in function zgfx_decompress_segment() that results in a memory corruption and probably even a remote code execution.
Summary: VUL-0: CVE-2018-8784: freerdp: Heap-Based Buffer Overflow in function zgfx_de...
Status: RESOLVED FIXED
Alias: CVE-2018-8784
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P2 - High : Major
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL:
Whiteboard: CVSSv3:SUSE:CVE-2018-8784:8.8:(AV:N/A...
Keywords:
Depends on:
Blocks:
 
Reported: 2018-11-20 11:02 UTC by Johannes Weberhofer
Modified: 2024-06-26 10:30 UTC (History)
2 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Johannes Weberhofer 2018-11-20 11:02:10 UTC
* CVE-2018-8789
* CVE-2018-8785
* CVE-2018-8786
* CVE-2018-8787
* CVE-2018-8788
* CVE-2018-8784
Comment 1 Johannes Weberhofer 2018-11-20 11:27:03 UTC
I have prepared and tested https://build.opensuse.org/request/show/650364

I think that upgrades for all supported platforms should be prepared including the Remmina package.
Comment 2 Swamp Workflow Management 2018-11-20 13:20:17 UTC
This is an autogenerated message for OBS integration:
This bug (1116708) was mentioned in
https://build.opensuse.org/request/show/650375 Factory / freerdp
Comment 3 Marcus Meissner 2018-11-30 16:30:36 UTC
switch to use  CVE-2018-8784 for this bug
Comment 6 Swamp Workflow Management 2019-01-21 17:12:48 UTC
SUSE-SU-2019:0134-1: An update that solves 8 vulnerabilities and has two fixes is now available.

Category: security (important)
Bug References: 1085416,1087240,1104918,1116708,1117963,1117964,1117965,1117966,1117967,1120507
CVE References: CVE-2018-0886,CVE-2018-1000852,CVE-2018-8784,CVE-2018-8785,CVE-2018-8786,CVE-2018-8787,CVE-2018-8788,CVE-2018-8789
Sources used:
SUSE Linux Enterprise Workstation Extension 12-SP4 (src):    freerdp-2.0.0~git.1463131968.4e66df7-12.8.1
SUSE Linux Enterprise Workstation Extension 12-SP3 (src):    freerdp-2.0.0~git.1463131968.4e66df7-12.8.1
SUSE Linux Enterprise Software Development Kit 12-SP4 (src):    freerdp-2.0.0~git.1463131968.4e66df7-12.8.1
SUSE Linux Enterprise Software Development Kit 12-SP3 (src):    freerdp-2.0.0~git.1463131968.4e66df7-12.8.1
SUSE Linux Enterprise Desktop 12-SP4 (src):    freerdp-2.0.0~git.1463131968.4e66df7-12.8.1
SUSE Linux Enterprise Desktop 12-SP3 (src):    freerdp-2.0.0~git.1463131968.4e66df7-12.8.1
Comment 7 Felix Zhang 2019-01-22 11:29:55 UTC
Fix released. Reassign to security experts.
Comment 8 Swamp Workflow Management 2019-01-29 14:22:47 UTC
openSUSE-SU-2019:0096-1: An update that solves 8 vulnerabilities and has two fixes is now available.

Category: security (important)
Bug References: 1085416,1087240,1104918,1116708,1117963,1117964,1117965,1117966,1117967,1120507
CVE References: CVE-2018-0886,CVE-2018-1000852,CVE-2018-8784,CVE-2018-8785,CVE-2018-8786,CVE-2018-8787,CVE-2018-8788,CVE-2018-8789
Sources used:
openSUSE Leap 42.3 (src):    freerdp-2.0.0~git.1463131968.4e66df7-13.1
Comment 11 Swamp Workflow Management 2019-03-04 20:57:32 UTC
SUSE-SU-2019:0539-1: An update that solves 8 vulnerabilities and has four fixes is now available.

Category: security (important)
Bug References: 1085416,1087240,1103557,1104918,1112028,1116708,1117963,1117964,1117965,1117966,1117967,1120507
CVE References: CVE-2018-0886,CVE-2018-1000852,CVE-2018-8784,CVE-2018-8785,CVE-2018-8786,CVE-2018-8787,CVE-2018-8788,CVE-2018-8789
Sources used:
SUSE Linux Enterprise Workstation Extension 15 (src):    freerdp-2.0.0~rc4-3.3.1
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 (src):    freerdp-2.0.0~rc4-3.3.1
Comment 12 Swamp Workflow Management 2019-03-13 23:15:23 UTC
openSUSE-SU-2019:0325-1: An update that solves 8 vulnerabilities and has four fixes is now available.

Category: security (important)
Bug References: 1085416,1087240,1103557,1104918,1112028,1116708,1117963,1117964,1117965,1117966,1117967,1120507
CVE References: CVE-2018-0886,CVE-2018-1000852,CVE-2018-8784,CVE-2018-8785,CVE-2018-8786,CVE-2018-8787,CVE-2018-8788,CVE-2018-8789
Sources used:
openSUSE Leap 15.0 (src):    freerdp-2.0.0~rc4-lp150.2.3.1
Comment 13 Marcus Meissner 2019-08-30 05:55:54 UTC
released
Comment 16 Swamp Workflow Management 2020-08-18 19:16:10 UTC
SUSE-SU-2020:2272-1: An update that fixes 46 vulnerabilities is now available.

Category: security (important)
Bug References: 1004108,1050699,1050704,1050708,1050711,1050712,1050714,1085416,1087240,1090677,1103557,1104918,1112028,1116708,1117963,1117964,1117965,1117966,1117967,1120507,1129193,1169679,1169748,1171441,1171443,1171444,1171445,1171446,1171447,1171674,1173247,1173605,1174200,1174321
CVE References: CVE-2017-2834,CVE-2017-2835,CVE-2017-2836,CVE-2017-2837,CVE-2017-2838,CVE-2017-2839,CVE-2018-0886,CVE-2018-1000852,CVE-2018-8784,CVE-2018-8785,CVE-2018-8786,CVE-2018-8787,CVE-2018-8788,CVE-2018-8789,CVE-2020-11017,CVE-2020-11018,CVE-2020-11019,CVE-2020-11038,CVE-2020-11039,CVE-2020-11040,CVE-2020-11041,CVE-2020-11043,CVE-2020-11085,CVE-2020-11086,CVE-2020-11087,CVE-2020-11088,CVE-2020-11089,CVE-2020-11095,CVE-2020-11096,CVE-2020-11097,CVE-2020-11098,CVE-2020-11099,CVE-2020-11521,CVE-2020-11522,CVE-2020-11523,CVE-2020-11524,CVE-2020-11525,CVE-2020-11526,CVE-2020-13396,CVE-2020-13397,CVE-2020-13398,CVE-2020-15103,CVE-2020-4030,CVE-2020-4031,CVE-2020-4032,CVE-2020-4033
JIRA References: 
Sources used:
SUSE Linux Enterprise Workstation Extension 12-SP5 (src):    freerdp-2.1.2-12.20.1, vinagre-3.20.2-16.3.3
SUSE Linux Enterprise Software Development Kit 12-SP5 (src):    freerdp-2.1.2-12.20.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.