Bug 1050711 (CVE-2017-2839)

Summary: VUL-0: CVE-2017-2839: freerdp: Client License Read Challenge Packet Denial of Service
Product: [Novell Products] SUSE Security Incidents Reporter: Johannes Segitz <jsegitz>
Component: IncidentsAssignee: Security Team bot <security-team>
Status: RESOLVED FIXED QA Contact: Security Team bot <security-team>
Severity: Normal    
Priority: P3 - Medium CC: astieger, smash_bz
Version: unspecified   
Target Milestone: ---   
Hardware: Other   
OS: Other   
URL: https://smash.suse.de/issue/189165/
Whiteboard: CVSSv3:RedHat:CVE-2017-2839:5.3:(AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H) CVSSv3:SUSE:CVE-2017-2839:6.5:(AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H) CVSSv2:SUSE:CVE-2017-2839:4.3:(AV:N/AC:M/Au:N/C:N/I:N/A:P)
Found By: Security Response Team Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---

Description Johannes Segitz 2017-07-26 13:32:26 UTC
https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0341

A specially crafted challenge packet can cause the program termination leading to a denial of service condition. An attacker can compromise the server or use man in the middle to trigger this vulnerability.

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1475234
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-2839
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2839
Comment 4 Swamp Workflow Management 2017-08-22 19:07:45 UTC
SUSE-SU-2017:2234-1: An update that fixes 6 vulnerabilities is now available.

Category: security (important)
Bug References: 1050699,1050704,1050708,1050711,1050712,1050714
CVE References: CVE-2017-2834,CVE-2017-2835,CVE-2017-2836,CVE-2017-2837,CVE-2017-2838,CVE-2017-2839
Sources used:
SUSE Linux Enterprise Workstation Extension 12-SP3 (src):    freerdp-2.0.0~git.1463131968.4e66df7-12.3.2
SUSE Linux Enterprise Workstation Extension 12-SP2 (src):    freerdp-2.0.0~git.1463131968.4e66df7-12.3.2
SUSE Linux Enterprise Software Development Kit 12-SP3 (src):    freerdp-2.0.0~git.1463131968.4e66df7-12.3.2
SUSE Linux Enterprise Software Development Kit 12-SP2 (src):    freerdp-2.0.0~git.1463131968.4e66df7-12.3.2
SUSE Linux Enterprise Desktop 12-SP3 (src):    freerdp-2.0.0~git.1463131968.4e66df7-12.3.2
SUSE Linux Enterprise Desktop 12-SP2 (src):    freerdp-2.0.0~git.1463131968.4e66df7-12.3.2
Comment 5 Andreas Stieger 2017-09-02 12:21:50 UTC
done
Comment 6 Swamp Workflow Management 2017-09-02 16:08:45 UTC
openSUSE-SU-2017:2332-1: An update that fixes 6 vulnerabilities is now available.

Category: security (important)
Bug References: 1050699,1050704,1050708,1050711,1050712,1050714
CVE References: CVE-2017-2834,CVE-2017-2835,CVE-2017-2836,CVE-2017-2837,CVE-2017-2838,CVE-2017-2839
Sources used:
openSUSE Leap 42.3 (src):    freerdp-2.0.0~git.1463131968.4e66df7-6.1
openSUSE Leap 42.2 (src):    freerdp-2.0.0~git.1463131968.4e66df7-3.3.1
Comment 9 Swamp Workflow Management 2020-08-18 19:15:14 UTC
SUSE-SU-2020:2272-1: An update that fixes 46 vulnerabilities is now available.

Category: security (important)
Bug References: 1004108,1050699,1050704,1050708,1050711,1050712,1050714,1085416,1087240,1090677,1103557,1104918,1112028,1116708,1117963,1117964,1117965,1117966,1117967,1120507,1129193,1169679,1169748,1171441,1171443,1171444,1171445,1171446,1171447,1171674,1173247,1173605,1174200,1174321
CVE References: CVE-2017-2834,CVE-2017-2835,CVE-2017-2836,CVE-2017-2837,CVE-2017-2838,CVE-2017-2839,CVE-2018-0886,CVE-2018-1000852,CVE-2018-8784,CVE-2018-8785,CVE-2018-8786,CVE-2018-8787,CVE-2018-8788,CVE-2018-8789,CVE-2020-11017,CVE-2020-11018,CVE-2020-11019,CVE-2020-11038,CVE-2020-11039,CVE-2020-11040,CVE-2020-11041,CVE-2020-11043,CVE-2020-11085,CVE-2020-11086,CVE-2020-11087,CVE-2020-11088,CVE-2020-11089,CVE-2020-11095,CVE-2020-11096,CVE-2020-11097,CVE-2020-11098,CVE-2020-11099,CVE-2020-11521,CVE-2020-11522,CVE-2020-11523,CVE-2020-11524,CVE-2020-11525,CVE-2020-11526,CVE-2020-13396,CVE-2020-13397,CVE-2020-13398,CVE-2020-15103,CVE-2020-4030,CVE-2020-4031,CVE-2020-4032,CVE-2020-4033
JIRA References: 
Sources used:
SUSE Linux Enterprise Workstation Extension 12-SP5 (src):    freerdp-2.1.2-12.20.1, vinagre-3.20.2-16.3.3
SUSE Linux Enterprise Software Development Kit 12-SP5 (src):    freerdp-2.1.2-12.20.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.