目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2020-11019 PoC — FreeRDP 缓冲区错误漏洞

来源
关联漏洞
标题: FreeRDP 缓冲区错误漏洞 (CVE-2020-11019)
Description:FreeRDP是FreeRDP团队的一款开源的远程桌面协议(RDP)的实现。 FreeRDP 2.0.0及之前版本中存在缓冲区错误漏洞,该漏洞源于当记录器设置为‘WLOG_TRACE’时,程序读取了无效的数组索引。攻击者可利用该漏洞导致应用程序崩溃,数据将被以字符串的形式打印到本地终端。
Description
In FreeRDP less than or equal to 2.0.0, when running with logger set to "WLOG_TRACE", a possible crash of application could occur due to a read of an invalid array index. Data could be printed as string to local terminal. This has been fixed in 2.1.0. CVE project by @Sn0wAlice
介绍
# CVE-2020-11019

In FreeRDP less than or equal to 2.0.0, when running with logger set to "WLOG_TRACE", a possible crash of application could occur due to a read of an invalid array index. Data could be printed as string to local terminal. This has been fixed in 2.1.0.

| authentication | complexity | vector |
| --- | --- | --- |
| SINGLE | LOW | NETWORK |

| confidentiality | integrity | availability |
| --- | --- | --- |
| NONE | NONE | PARTIAL |

## CVSS Score: **4**

## References

* https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-wvrr-2f4r-hjvh

* http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00080.html

## Brut File

* [CVE-2020-11019.json](./data_brut.json)



## About this repository
This repository is part of the project [Live Hack CVE](https://github.com/Live-Hack-CVE). Made by [Sn0wAlice](https://github.com/Sn0wAlice) for the people that care about security and need to have a feed of the latest CVEs. Hope you enjoy it, don't forget to star the repo and follow me on [Twitter](https://twitter.com/Sn0wAlice) and [Github](https://github.com/Sn0wAlice)
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →