Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-91960

Опубликовано: 15 сент. 2026
Источник: debian
EPSS Низкий

Описание

FreeRDP versions before 3.31.0 contain an integer overflow in WinPR's Stream_EnsureRemainingCapacity function that allows remote attackers to cause denial of service. A malicious RD Gateway peer can send a WebSocket Ping frame with a crafted 64-bit extended payload length to trigger integer wraparound, resulting in a double free that crashes the FreeRDP client during connection.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
freerdp3fixed3.31.0+dfsg-1package
freerdp3not-affectedtrixiepackage
freerdp2not-affectedpackage

Примечания

  • https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-vccg-35r5-8jrf

EPSS

Процентиль: 38%
0.00442
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
3 дня назад

[GHSA-vccg-35r5-8jrf: Stream_EnsureCapacity still overflows]

CVSS3: 6.5
redhat
3 дня назад

FreeRDP versions before 3.31.0 contain an integer overflow in WinPR's Stream_EnsureRemainingCapacity function that allows remote attackers to cause denial of service. A malicious RD Gateway peer can send a WebSocket Ping frame with a crafted 64-bit extended payload length to trigger integer wraparound, resulting in a double free that crashes the FreeRDP client during connection.

CVSS3: 6.5
nvd
3 дня назад

FreeRDP versions before 3.31.0 contain an integer overflow in WinPR's Stream_EnsureRemainingCapacity function that allows remote attackers to cause denial of service. A malicious RD Gateway peer can send a WebSocket Ping frame with a crafted 64-bit extended payload length to trigger integer wraparound, resulting in a double free that crashes the FreeRDP client during connection.

CVSS3: 6.5
github
3 дня назад

FreeRDP versions before 3.31.0 contain an integer overflow in WinPR's Stream_EnsureRemainingCapacity function that allows remote attackers to cause denial of service. A malicious RD Gateway peer can send a WebSocket Ping frame with a crafted 64-bit extended payload length to trigger integer wraparound, resulting in a double free that crashes the FreeRDP client during connection.

EPSS

Процентиль: 38%
0.00442
Низкий