rdesktop: Directory Traversal A vulnerability which allows a remote attacking server to read or overwrite arbitrary files has been found in rdesktop. rdesktop 2012-10-18 2012-10-18 364191 remote 1.7.0 1.7.0

rdesktop is a Remote Desktop Protocol (RDP) Client.

A vulnerability has been discovered in rdesktop. Please review the CVE identifier referenced below for details.

Remote RDP servers may be able to read or overwrite arbitrary files via a .. (dot dot) in a pathname.

There is no known workaround at this time.

All rdesktop users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=net-misc/rdesktop-1.7.0"
CVE-2011-1595 underling craig