« Volver al listado

CVE-2018-8791

Estado: ModificadaAlta (7.5)—

Las versiones de rdesktop, hasta la v1.8.3 (inclusivas), contienen una lectura fuera de límites en la función rdpdr_process(), lo que resulta en una fuga de información.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2018-8791",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve@checkpoint.com",
      "affectedData": [
        {
          "vendor": "Check Point Software Technologies Ltd.",
          "product": "rdesktop",
          "versions": [
            {
              "status": "affected",
              "version": "All versions up to and including v1.8.3"
            }
          ]
        }
      ]
    }
  ],
  "published": "2019-02-05T20:29:00.367",
  "references": [
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00040.html",
      "source": "cve@checkpoint.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/106938",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "cve@checkpoint.com"
    },
    {
      "url": "https://github.com/rdesktop/rdesktop/commit/4dca546d04321a610c1835010b5dad85163b65e1",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "cve@checkpoint.com"
    },
    {
      "url": "https://lists.debian.org/debian-lts-announce/2019/02/msg00030.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "cve@checkpoint.com"
    },
    {
      "url": "https://research.checkpoint.com/reverse-rdp-attack-code-execution-on-rdp-clients/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cve@checkpoint.com"
    },
    {
      "url": "https://security.gentoo.org/glsa/201903-06",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cve@checkpoint.com"
    },
    {
      "url": "https://www.debian.org/security/2019/dsa-4394",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cve@checkpoint.com"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00040.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/106938",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/rdesktop/rdesktop/commit/4dca546d04321a610c1835010b5dad85163b65e1",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.debian.org/debian-lts-announce/2019/02/msg00030.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://research.checkpoint.com/reverse-rdp-attack-code-execution-on-rdp-clients/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://security.gentoo.org/glsa/201903-06",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.debian.org/security/2019/dsa-4394",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cve@checkpoint.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-126"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-125"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function rdpdr_process() that results in an information leak."
    },
    {
      "lang": "es",
      "value": "Las versiones de rdesktop, hasta la v1.8.3 (inclusivas), contienen una lectura fuera de límites en la función rdpdr_process(), lo que resulta en una fuga de información."
    }
  ],
  "lastModified": "2026-06-17T02:05:23.790",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:rdesktop:rdesktop:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "223ED7FC-79EF-4324-82AE-D3794128C7A3",
              "versionEndIncluding": "1.8.3"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C11E6FB0-C8C0-4527-9AA0-CB9B316F8F43"
            },
            {
              "criteria": "cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DEECE5FC-CACF-4496-A3E7-164736409252"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@checkpoint.com"
}