Описание
HuffmanTree_makeFromFrequencies in lodepng.c in LodePNG through 2019-09-28, as used in WinPR in FreeRDP and other products, has a memory leak because a supplied realloc pointer (i.e., the first argument to realloc) is also used for a realloc return value.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| freerdp2 | fixed | 2.0.0~git20190204.1.2693389a+dfsg1-2 | package | |
| freerdp2 | fixed | 2.0.0~git20190204.1.2693389a+dfsg1-1+deb10u1 | buster | package |
| freerdp | removed | package | ||
| freerdp | not-affected | stretch | package |
Примечания
https://github.com/FreeRDP/FreeRDP/issues/5645
https://github.com/FreeRDP/FreeRDP/commit/9fee4ae076b1ec97b97efb79ece08d1dab4df29a (v2.0.0)
Multiple source packages embed a copy of lodepng (openscad, tbb, mame, passage,
quakespasm, simbody, paraview, dart, drumgizmo, doxygen, love, libtcod, f
cubicsdr, nestopia, refind, zopfli, montage), but don't seem security-relevant
embedded from: https://github.com/FreeRDP/FreeRDP/commit/1c345834079f3c8b581204e36b0cf0f3c021c445 (2.0.0-beta1+android10)
to: https://github.com/FreeRDP/FreeRDP/commit/605b6b6233e52151d208b7faa87691533a857b07 (3.0.0-beta2)
EPSS
Связанные уязвимости
HuffmanTree_makeFromFrequencies in lodepng.c in LodePNG through 2019-09-28, as used in WinPR in FreeRDP and other products, has a memory leak because a supplied realloc pointer (i.e., the first argument to realloc) is also used for a realloc return value.
HuffmanTree_makeFromFrequencies in lodepng.c in LodePNG through 2019-09-28, as used in WinPR in FreeRDP and other products, has a memory leak because a supplied realloc pointer (i.e., the first argument to realloc) is also used for a realloc return value.
HuffmanTree_makeFromFrequencies in lodepng.c in LodePNG through 2019-09-28, as used in WinPR in FreeRDP and other products, has a memory leak because a supplied realloc pointer (i.e., the first argument to realloc) is also used for a realloc return value.
EPSS