CVE-2008-1803
EPSS 16.4%
Description
Integer signedness error in the xrealloc function (rdesktop.c) in RDesktop 1.5.0 allows remote attackers to execute arbitrary code via unknown parameters that trigger a heap-based overflow. NOTE: the role of the channel_process function was not specified by the original researcher.
How to fix CVE-2008-1803
To remediate CVE-2008-1803, upgrade the affected package to a fixed version below.
- Debian/rdesktop—upgrade to 1.5.0-4+cvs20071006 or later
Is CVE-2008-1803 being exploited?
Moderate — EPSS is 16.4%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 1.5.0-4+cvs20071006