CVE-2008-1801

Publication date 12 May 2008

Last updated 24 July 2024


Ubuntu priority

Integer underflow in the iso_recv_msg function (iso.c) in rdesktop 1.5.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a Remote Desktop Protocol (RDP) request with a small length field.

Status

Package Ubuntu Release Status
rdesktop 8.04 LTS hardy
Fixed 1.5.0-3+cvs20071006ubuntu0.1
7.10 gutsy
Fixed 1.5.0-2ubuntu0.1
7.04 feisty
Fixed 1.5.0-1ubuntu1.1
6.06 LTS dapper
Fixed 1.4.1-1.1ubuntu0.6.06.1

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
rdesktop

References

Related Ubuntu Security Notices (USN)

    • USN-646-1
    • rdesktop vulnerabilities
    • 18 September 2008

Other references