A vulnerability which allows a remote attacking server to read or overwrite arbitrary files has been found in rdesktop.
|Package||net-misc/rdesktop on all architectures|
|Affected versions||< 1.7.0|
|Unaffected versions||>= 1.7.0|
rdesktop is a Remote Desktop Protocol (RDP) Client.
A vulnerability has been discovered in rdesktop. Please review the CVE identifier referenced below for details.
Remote RDP servers may be able to read or overwrite arbitrary files via a .. (dot dot) in a pathname.
There is no known workaround at this time.
All rdesktop users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose ">=net-misc/rdesktop-1.7.0"
October 18, 2012
October 18, 2012: 1