4.3
CVSSv2

CVE-2011-1595

Published: 24/05/2011 Updated: 05/04/2013
CVSS v2 Base Score: 4.3 | Impact Score: 6.4 | Exploitability Score: 3.2
VMScore: 383
Vector: AV:A/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

Directory traversal vulnerability in the disk_create function in disk.c in rdesktop prior to 1.7.0, when disk redirection is enabled, allows remote RDP servers to read or overwrite arbitrary files via a .. (dot dot) in a pathname.

Vulnerable Product Search on Vulmon Subscribe to Product

rdesktop rdesktop 1.0.0

rdesktop rdesktop 1.1.0

rdesktop rdesktop 1.5.0

rdesktop rdesktop 1.4.0

rdesktop rdesktop

rdesktop rdesktop 1.2.0

rdesktop rdesktop 1.3.0

rdesktop rdesktop 1.3.1

rdesktop rdesktop 1.4.1

Vendor Advisories

An attacker could access your files if rdesktop connected to a malicious server ...