FreeRDP prior to version 2.0.0-rc4 contains several Out-Of-Bounds Reads in the NTLM Authentication module that results in a Denial of Service (segfault). Upstream patch: https://github.com/FreeRDP/FreeRDP/commit/2ee663f39dc8dac3d9988e847db19b2d7e3ac8c6
Created freerdp tracking bugs for this issue: Affects: epel-6 [bug 1671370]
Statement: This issue did not affect the versions of freerdp as shipped with Red Hat Enterprise Linux 6 and 7 as they did not include the vulnerable code.