FS#57838 - [freerdp] Fix broken RDP connection after Microsoft's March 2018 CredSSP vuln fix (CVE-2018-0886)

Attached to Project: Community Packages
Opened by Pascal Ernster (hardfalcon) - Wednesday, 14 March 2018, 13:45 GMT
Last edited by Sergej Pupykin (sergej) - Friday, 16 March 2018, 09:42 GMT
Task Type Bug Report
Category Packages
Status Closed
Assigned To Sergej Pupykin (sergej)
Architecture All
Severity High
Priority Normal
Reported Version
Due in Version Undecided
Due Date Undecided
Percent Complete 100%
Votes 2
Private No

Details

freerdp 1:2.0.0_rc1-1 cannot be used to perform RDP connections to Windows machines to which Microsofts March 2018 fix for CVE-2018-0886 was installed:

https://github.com/FreeRDP/FreeRDP/issues/4449

https://msdn.microsoft.com/en-us/library/mt752485.aspx

Upstream has merged a pull request which fixes the issue in FreeRDP:

https://github.com/FreeRDP/FreeRDP/commit/f8baeb72470f3ada14fdf6f8a13b67543340621b

Please update FreeRDP the above version (or a newer version).
This task depends upon

Closed by  Sergej Pupykin (sergej)
Friday, 16 March 2018, 09:42 GMT
Reason for closing:  Fixed
Comment by Joschka Thurner (jthurner) - Thursday, 15 March 2018, 09:55 GMT
The patch added to git master works well for 2.0.0_rc1 but fails to apply due to minor changes since the last release.
See attached PKGBUILD + back-ported patch if you need to get a working version quickly.

Loading...