CVE-2008-1803
Last modified
CVE-2008-1803 is a vulnerability of currently unknown severity. Integer signedness error in the xrealloc function (rdesktop.c) in RDesktop 1.5.0 allows remote attackers to execute arbitrary code via unknown parameters that trigger a heap-based overflow. NOTE: the role of the channel_process function was not specified by the original researcher.. EPSS estimates a 6.74% chance of exploitation in the next 30 days.
Description
Integer signedness error in the xrealloc function (rdesktop.c) in RDesktop 1.5.0 allows remote attackers to execute arbitrary code via unknown parameters that trigger a heap-based overflow. NOTE: the role of the channel_process function was not specified by the original researcher.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Rdesktop | Rdesktop | 1.5.0 |
References
- http://secunia.com/advisories/30118Vendor Advisory
- http://secunia.com/advisories/30248Vendor Advisory
- http://secunia.com/advisories/30713Vendor Advisory
- http://secunia.com/advisories/31224Vendor Advisory
- http://secunia.com/advisories/31928Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2008-0575.htmlVendor Advisory
- http://www.vupen.com/english/advisories/2008/1467/referencesVendor Advisory
- http://www.vupen.com/english/advisories/2008/2403Vendor Advisory
- http://secunia.com/advisories/30118Vendor Advisory
- http://secunia.com/advisories/30248Vendor Advisory
- http://secunia.com/advisories/30713Vendor Advisory
- http://secunia.com/advisories/31224Vendor Advisory
- http://secunia.com/advisories/31928Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2008-0575.htmlVendor Advisory
- http://www.vupen.com/english/advisories/2008/1467/referencesVendor Advisory
- http://www.vupen.com/english/advisories/2008/2403Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-1803?
How severe is CVE-2008-1803?
How do I fix CVE-2008-1803?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2008
- CVE-2008-1797Unspecified vulnerability in Secure Computing Webwasher 5.30…
- CVE-2008-1798Directory traversal vulnerability in forum/kietu/libs/calend…
- CVE-2008-1799Directory traversal vulnerability in thumbnails.php in sabro…
- CVE-2008-1800Multiple cross-site scripting (XSS) vulnerabilities in index…
- CVE-2008-1801Integer underflow in the iso_recv_msg function (iso.c) in rd…
- CVE-2008-1802Buffer overflow in the process_redirect_pdu (rdp.c) function…
- CVE-2008-1804preprocessors/spp_frag3.c in Sourcefire Snort before 2.8.1 d…
- CVE-2008-1805Incomplete blacklist vulnerability in Skype 3.6.0.248, and o…
- CVE-2008-1806Integer overflow in FreeType2 before 2.3.6 allows context-de…
- CVE-2008-1807FreeType2 before 2.3.6 allow context-dependent attackers to …
- CVE-2008-1808Multiple off-by-one errors in FreeType2 before 2.3.6 allow c…
- CVE-2008-1809Heap-based buffer overflow in Novell eDirectory 8.7.3 before…
Are you affected by CVE-2008-1803?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
