[Bug 248198] net/freerdp: Update to 2.2.0 with fixed CVE-2020-15103

bugzilla-noreply at freebsd.org bugzilla-noreply at freebsd.org
Thu Jul 23 08:07:02 UTC 2020


https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=248198

            Bug ID: 248198
           Summary: net/freerdp: Update to 2.2.0 with fixed CVE-2020-15103
           Product: Ports & Packages
           Version: Latest
          Hardware: Any
               URL: https://www.freerdp.com/2020/07/20/2_2_0-released
                OS: Any
            Status: New
          Severity: Affects Many People
          Priority: ---
         Component: Individual Port(s)
          Assignee: kevans at freebsd.org
          Reporter: vvd at unislabs.com
          Assignee: kevans at freebsd.org
             Flags: maintainer-feedback?(kevans at freebsd.org)
 Attachment #216690 maintainer-approval?
             Flags:
             Flags: maintainer-feedback?, merge-quarterly?

Created attachment 216690
  --> https://bugs.freebsd.org/bugzilla/attachment.cgi?id=216690&action=edit
Update to 2.2.0 with fixed CVE-2020-15103

https://github.com/FreeRDP/FreeRDP/releases/tag/2.2.0

FreeRDP version 2.2.0
    SECURITY: CVE-2020-15103 - Integer overflow due to missing input sanitation
in rdpegfx channel
    #6263 Sound & mic - filter GSM codec for microphone redirection
    #6335: windows client title length
    #6370 - "Alternate Secondary Drawing Order UNKNOWN"
    #6298 - remoteapp with dialog is disconnecting when it loses focus
    #6299 - v2.1.2: Can't connect to Windows7
Noteworty changes:
    fix: memory leak in nsc
    urbdrc
        some fixes and improvements
    build
        use cmake to detect getlogin_r
        improve asan checks/detection
    server/proxy
        new: support for heartbeats
        new: support for rail handshake ex flags
        fix: possible race condition with redirects

Tested on 12.1 amd64: make test/check-plist/install and run.

-- 
You are receiving this mail because:
You are the assignee for the bug.


More information about the freebsd-ports-bugs mailing list