A vulnerability which allows a remote attacking server to read or overwrite arbitrary files has been found in rdesktop.
Package | net-misc/rdesktop on all architectures |
---|---|
Affected versions | < 1.7.0 |
Unaffected versions | >= 1.7.0 |
rdesktop is a Remote Desktop Protocol (RDP) Client.
A vulnerability has been discovered in rdesktop. Please review the CVE identifier referenced below for details.
Remote RDP servers may be able to read or overwrite arbitrary files via a .. (dot dot) in a pathname.
There is no known workaround at this time.
All rdesktop users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose ">=net-misc/rdesktop-1.7.0"
Release date
October 18, 2012
Latest revision
October 18, 2012: 1
Severity
normal
Exploitable
remote
Bugzilla entries