Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-39317

Опубликовано: 16 нояб. 2022
Источник: debian
EPSS Низкий

Описание

FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing a range check for input offset index in ZGFX decoder. A malicious server can trick a FreeRDP based client to read out of bound data and try to decode it. This issue has been addressed in version 2.9.0. There are no known workarounds for this issue.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
freerdp2fixed2.9.0+dfsg1-1package
freerdp2no-dsabullseyepackage
freerdp2no-dsabusterpackage

Примечания

  • https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-99cm-4gw7-c8jh

EPSS

Процентиль: 19%
0.00062
Низкий

Связанные уязвимости

CVSS3: 4.6
ubuntu
около 3 лет назад

FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing a range check for input offset index in ZGFX decoder. A malicious server can trick a FreeRDP based client to read out of bound data and try to decode it. This issue has been addressed in version 2.9.0. There are no known workarounds for this issue.

CVSS3: 3.7
redhat
около 3 лет назад

FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing a range check for input offset index in ZGFX decoder. A malicious server can trick a FreeRDP based client to read out of bound data and try to decode it. This issue has been addressed in version 2.9.0. There are no known workarounds for this issue.

CVSS3: 4.6
nvd
около 3 лет назад

FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing a range check for input offset index in ZGFX decoder. A malicious server can trick a FreeRDP based client to read out of bound data and try to decode it. This issue has been addressed in version 2.9.0. There are no known workarounds for this issue.

CVSS3: 4.6
fstec
около 3 лет назад

Уязвимость декодера ZGFX реализации протокола удалённого рабочего стола FreeRDP, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

suse-cvrf
почти 3 года назад

Security update for freerdp

EPSS

Процентиль: 19%
0.00062
Низкий