CVE-2020-11039

MEDIUM6.8EPSS 0.17%
Published: 5/29/2020Modified: 4/28/2026
Also known as:DEBIAN-CVE-2020-11039

Description

In FreeRDP less than or equal to 2.0.0, when using a manipulated server with USB redirection enabled (nearly) arbitrary memory can be read and written due to integer overflows in length checks. This has been patched in 2.1.0.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM6.8CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:L

References (1)