[ubuntu/jammy-proposed] freerdp2 2.3.0+dfsg1-2ubuntu2 (Accepted)

Marc Deslauriers marc.deslauriers at ubuntu.com
Thu Dec 9 15:12:13 UTC 2021


freerdp2 (2.3.0+dfsg1-2ubuntu2) jammy; urgency=medium

  [ Leonidas Da Silva Barbosa ]
  * SECURITY UPDATE: OOB Write
    - debian/patches/CVE-2021-41159-and-41160.patch: add checks
      in multiple files and added checks for bitmap
      width and heigth values in order to avoid out
      of bounds write in
      libfreerdp/core/gateway/ncacn_http.c,
      libfreerdp/core/gateway/rdg.c,
      libfreerdp/core/gateway/rpc.c,
      libfreerdp/core/gateway/rpc.h,
      libfreerdp/core/gateway/rpc_bind.c,
      libfreerdp/core/gateway/rpc_bind.h,
      libfreerdp/core/gateway/rpc_client.c,
      libfreerdp/core/gateway/rpc_client.h,
      libfreerdp/core/gateway/rpc_fault.c,
      libfreerdp/core/gateway/rts.c,
      libfreerdp/core/gateway/rts.h,
      libfreerdp/core/gateway/rts_signature.c,
      libfreerdp/core/gateway/rts_signature.h,
      libfreerdp/core/gateway/tsg.c,
      libfreerdp/core/orders.c,
      libfreerdp/core/surface.c,
      libfreerdp/core/update.c.
    - CVE-2021-41159
    - CVE-2021-41160

Date: Thu, 09 Dec 2021 09:46:59 -0500
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/+source/freerdp2/2.3.0+dfsg1-2ubuntu2
-------------- next part --------------
Format: 1.8
Date: Thu, 09 Dec 2021 09:46:59 -0500
Source: freerdp2
Built-For-Profiles: noudeb
Architecture: source
Version: 2.3.0+dfsg1-2ubuntu2
Distribution: jammy
Urgency: medium
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Changes:
 freerdp2 (2.3.0+dfsg1-2ubuntu2) jammy; urgency=medium
 .
   [ Leonidas Da Silva Barbosa ]
   * SECURITY UPDATE: OOB Write
     - debian/patches/CVE-2021-41159-and-41160.patch: add checks
       in multiple files and added checks for bitmap
       width and heigth values in order to avoid out
       of bounds write in
       libfreerdp/core/gateway/ncacn_http.c,
       libfreerdp/core/gateway/rdg.c,
       libfreerdp/core/gateway/rpc.c,
       libfreerdp/core/gateway/rpc.h,
       libfreerdp/core/gateway/rpc_bind.c,
       libfreerdp/core/gateway/rpc_bind.h,
       libfreerdp/core/gateway/rpc_client.c,
       libfreerdp/core/gateway/rpc_client.h,
       libfreerdp/core/gateway/rpc_fault.c,
       libfreerdp/core/gateway/rts.c,
       libfreerdp/core/gateway/rts.h,
       libfreerdp/core/gateway/rts_signature.c,
       libfreerdp/core/gateway/rts_signature.h,
       libfreerdp/core/gateway/tsg.c,
       libfreerdp/core/orders.c,
       libfreerdp/core/surface.c,
       libfreerdp/core/update.c.
     - CVE-2021-41159
     - CVE-2021-41160
Checksums-Sha1:
 2f34399e8ecfb83f9a5f30c6c24c259bf6f2d2f0 3631 freerdp2_2.3.0+dfsg1-2ubuntu2.dsc
 34a0e9ae226337e860c2b3c500fa4074016d5c6f 91132 freerdp2_2.3.0+dfsg1-2ubuntu2.debian.tar.xz
 7c5cfa1ae97ab210afda4355b16d187b50f82946 15991 freerdp2_2.3.0+dfsg1-2ubuntu2_source.buildinfo
Checksums-Sha256:
 871baadc37a1168583ebe8bf6d7a881193f392d1dfe500891e35fc68d56ee803 3631 freerdp2_2.3.0+dfsg1-2ubuntu2.dsc
 f6d744e549663dc5d82784db18ed46c12735507d1fd841a261b7b3e0e90a3ee9 91132 freerdp2_2.3.0+dfsg1-2ubuntu2.debian.tar.xz
 3ea551dd677dcb2252b11ff8786ffdd9a510bf2b66a69e6365d4e0b32e469175 15991 freerdp2_2.3.0+dfsg1-2ubuntu2_source.buildinfo
Files:
 913ac2c4ed2cbde35257d9b3bb3e526e 3631 x11 optional freerdp2_2.3.0+dfsg1-2ubuntu2.dsc
 fa05e4b1a992b2d5a7b0cd9ffe0002fd 91132 x11 optional freerdp2_2.3.0+dfsg1-2ubuntu2.debian.tar.xz
 9fe13993fa704624b4410e1c281014cc 15991 x11 optional freerdp2_2.3.0+dfsg1-2ubuntu2_source.buildinfo
Original-Maintainer: Debian Remote Maintainers <debian-remote at lists.debian.org>


More information about the jammy-changes mailing list