freerdp2 2.0.0~git20180411.1.7a7b1802+dfsg1-2ubuntu0.1 source package in Ubuntu

Changelog

freerdp2 (2.0.0~git20180411.1.7a7b1802+dfsg1-2ubuntu0.1) cosmic-security; urgency=medium

  * SECURITY UPDATE: Heap based buffer overflow in zgfx_decompress_segment
    - debian/patches/CVE-2018-8784.patch: Add checks to ensure not to overflow output
      buffer in libfreerdp/codec/zgfx.c. Based on upstream patch.
    - CVE-2018-8784
  * SECURITY UPDATE: Heap based buffer overflow in zgfx_decompress
    - debian/patches/CVE-2018-8785.patch: Add checks to ensure not to overflow output
      buffer in libfreerdp/codec/zgfx.c. Based on upstream patch.
    - CVE-2018-8785
  * SECURITY UPDATE: Integer truncation in update_read_bitmap_update
    - debian/patches/CVE-2018-8786.patch: Promote count to 32-bit integer
      type to avoid integer truncation in libfreerdp/core/update.c. Based on
      upstream patch.
    - CVE-2018-8786
  * SECURITY UPDATE: Integer overflow in gdi_Bitmap_Decompress
    - debian/patches/CVE-2018-8787.patch: Check for and avoid possible
      integer overflow in libfreerdp/gdi/graphics.c. Based on upstream
      patch.
    - CVE-2018-8787
  * SECURITY UPDATE: Buffer overflow in nsc_rle_decode
    - debian/patches/CVE-2018-8788.patch: Check for lengths and avoid
      possible buffer overflow overflow in libfreerdp/codec/nsc.c and
      libfreerdp/codec/nsc_encode.c. Based on upstream patch.
    - CVE-2018-8788
  * SECURITY UPDATE: Out-of-bounds read in ntlm_read_message_fields_buffer
    - debian/patches/CVE-2018-8789.patch: Ensure to use 64-bit integer
      type when checking offset against stream length in
      winpr/libwinpr/sspi/NTLM/ntlm_message.c. Based on upstream patch.
    - CVE-2018-8789

 -- Alex Murray <email address hidden>  Mon, 10 Dec 2018 21:21:01 +1030

Upload details

Uploaded by:
Alex Murray on 2018-12-10
Uploaded to:
Cosmic
Original maintainer:
Ubuntu Developers
Architectures:
any
Section:
x11
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section
Cosmic updates on 2018-12-12 main misc
Cosmic security on 2018-12-12 main misc

Downloads

File Size SHA-256 Checksum
freerdp2_2.0.0~git20180411.1.7a7b1802+dfsg1.orig.tar.xz 3.5 MiB 26b458155b77b53700868153f3107f130ecfa49b093d241190e4e6511ec7b4d2
freerdp2_2.0.0~git20180411.1.7a7b1802+dfsg1-2ubuntu0.1.debian.tar.xz 45.1 KiB 0bbc6d5cd0bbfba5476d8a9f3668c75693b6c789c1f7a8e837a21677fb83acac
freerdp2_2.0.0~git20180411.1.7a7b1802+dfsg1-2ubuntu0.1.dsc 3.4 KiB 7974a4d2095ef4441cb3562408d83e92c7ed734c2433e1576bbbb889ee09650f

View changes file

Binary packages built by this source

freerdp2-dev: Free Remote Desktop Protocol library (development files)

 FreeRDP is a libre client/server implementation of the Remote
 Desktop Protocol (RDP).
 .
 This package contains the FreeRDP development files.

freerdp2-shadow-x11: FreeRDP x11 shadowing server

 FreeRDP is a libre client/server implementation of the Remote
 Desktop Protocol (RDP).
 .
 This package contains a "shadowing" server that can be used to
 share an already started X11 DISPLAY.

freerdp2-shadow-x11-dbgsym: debug symbols for freerdp2-shadow-x11
freerdp2-wayland: RDP client for Windows Terminal Services (wayland client)

 FreeRDP is a libre client/server implementation of the Remote
 Desktop Protocol (RDP).
 .
 Currently, the FreeRDP clients supports the following Windows Versions:
 .
  * Windows NT Server
  * Windows 2000 Terminal Server
  * Windows XP
  * Windows 2003 Server
  * Windows Vista
  * Windows 2008/2008r2/2011SBS Server
  * Windows 7
  * Windows 2012/2012r2 Server
  * Windows 8
  * Windows 10
 .
 This package contains the wayland based client.

freerdp2-wayland-dbgsym: debug symbols for freerdp2-wayland
freerdp2-x11: RDP client for Windows Terminal Services (X11 client)

 FreeRDP is a libre client/server implementation of the Remote
 Desktop Protocol (RDP).
 .
 Currently, the FreeRDP client supports the following Windows Versions:
 .
  * Windows NT Server
  * Windows 2000 Terminal Server
  * Windows XP
  * Windows 2003 Server
  * Windows Vista
  * Windows 2008/2008r2/2011SBS Server
  * Windows 7
  * Windows 2012/2012r2 Server
  * Windows 8
  * Windows 10
 .
 This package contains the X11 based client.

freerdp2-x11-dbgsym: debug symbols for freerdp2-x11
libfreerdp-client2-2: Free Remote Desktop Protocol library (client library)

 FreeRDP is a libre client/server implementation of the Remote
 Desktop Protocol (RDP).
 .
 This package contains the shared library for common client functionality.

libfreerdp-client2-2-dbgsym: debug symbols for libfreerdp-client2-2
libfreerdp-server2-2: Free Remote Desktop Protocol library (server library)

 FreeRDP is a libre client/server implementation of the Remote
 Desktop Protocol (RDP).
 .
 This package contains the shared library with common server functionality.

libfreerdp-server2-2-dbgsym: debug symbols for libfreerdp-server2-2
libfreerdp-shadow-subsystem2-2: FreeRDP Remote Desktop Protocol shadow subsystem libraries

 FreeRDP is a libre client/server implementation of the Remote
 Desktop Protocol (RDP).
 .
 This package contains the shadow subsystem libraries.

libfreerdp-shadow-subsystem2-2-dbgsym: debug symbols for libfreerdp-shadow-subsystem2-2
libfreerdp-shadow2-2: FreeRDP Remote Desktop Protocol shadow libraries

 FreeRDP is a libre client/server implementation of the Remote
 Desktop Protocol (RDP).
 .
 This package contains the shadow libraries.

libfreerdp-shadow2-2-dbgsym: debug symbols for libfreerdp-shadow2-2
libfreerdp2-2: Free Remote Desktop Protocol library (core library)

 FreeRDP is a libre client/server implementation of the Remote
 Desktop Protocol (RDP).
 .
 This package contains the shared library with all core functionality.

libfreerdp2-2-dbgsym: debug symbols for libfreerdp2-2
libuwac0-0: Using wayland as a client library

 Using wayland as a client (uwac) is a library to provide common
 functionality for wayland clients.
 .
 This package contains the using wayland as a client library.

libuwac0-0-dbgsym: debug symbols for libuwac0-0
libuwac0-dev: Using wayland as a client (development files)

 Using wayland as a client (uwac) is a library to provide common
 functionality for wayland clients.
 .
 This package contains the libuwac development files

libwinpr-tools2-2: Windows Portable Runtime Tools library

 FreeRDP is a libre client/server implementation of the Remote
 Desktop Protocol (RDP).
 .
 This package contains the shared library for Windows Portable Runtime
 utilities and tools.

libwinpr-tools2-2-dbgsym: debug symbols for libwinpr-tools2-2
libwinpr2-2: Windows Portable Runtime library

 WinPR is a spin-off project of FreeRDP which aims at providing a portable
 implementation of important portions of the Windows API. Just like FreeRDP,
 WinPR is released under the Apache license. Unlike Wine, WinPR does not provide
 binary compatibility, and does not require applications to be built for
 Windows. Instead, WinPR provides API compatibility for applications targeting
 non-Windows environments. When on Windows, the original native API is being
 used instead of the equivalent WinPR implementation, without having to modify
 the code using it.
 .
 This package contains the WinPR shared library.

libwinpr2-2-dbgsym: debug symbols for libwinpr2-2
libwinpr2-dev: Windows Portable Runtime library (development files)

 WinPR is a spin-off project of FreeRDP which aims at providing a portable
 implementation of important portions of the Windows API. Just like FreeRDP,
 WinPR is released under the Apache license. Unlike Wine, WinPR does not provide
 binary compatibility, and does not require applications to be built for
 Windows. Instead, WinPR provides API compatibility for applications targeting
 non-Windows environments. When on Windows, the original native API is being
 used instead of the equivalent WinPR implementation, without having to modify
 the code using it.
 .
 This package contains the WinPR development files.

winpr-utils: Windows Portable Runtime library command line utilities

 WinPR is a spin-off project of FreeRDP which aims at providing a portable
 implementation of important portions of the Windows API. Just like FreeRDP,
 WinPR is released under the Apache license. Unlike Wine, WinPR does not provide
 binary compatibility, and does not require applications to be built for
 Windows. Instead, WinPR provides API compatibility for applications targeting
 non-Windows environments. When on Windows, the original native API is being
 used instead of the equivalent WinPR implementation, without having to modify
 the code using it.
 .
 This package contains WinPR command line utils (winpr-hash, winpr-makecert).

winpr-utils-dbgsym: debug symbols for winpr-utils