Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4xh7-7c9f-cg88

Опубликовано: 15 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.3
CVSS3: 6.3

Описание

FreeRDP before 3.31.0 contains an integer overflow in the audin Apple backends when processing FramesPerPacket values from MSG_SNDIN_OPEN messages. Attackers can supply crafted FramesPerPacket values that cause AudioQueueAllocateBuffer size computation to wrap, resulting in undersized buffer allocation and potential out-of-bounds access.

FreeRDP before 3.31.0 contains an integer overflow in the audin Apple backends when processing FramesPerPacket values from MSG_SNDIN_OPEN messages. Attackers can supply crafted FramesPerPacket values that cause AudioQueueAllocateBuffer size computation to wrap, resulting in undersized buffer allocation and potential out-of-bounds access.

EPSS

Процентиль: 16%
0.00244
Низкий

5.3 Medium

CVSS4

6.3 Medium

CVSS3

Дефекты

CWE-131

Связанные уязвимости

CVSS3: 6.3
ubuntu
3 дня назад

[GHSA-f5p6-88mh-59vg: audin Apple backends perform overflow-prone buffer size arithmetic from server-controlled values]

CVSS3: 6.3
redhat
3 дня назад

FreeRDP before 3.31.0 contains an integer overflow in the audin Apple backends when processing FramesPerPacket values from MSG_SNDIN_OPEN messages. Attackers can supply crafted FramesPerPacket values that cause AudioQueueAllocateBuffer size computation to wrap, resulting in undersized buffer allocation and potential out-of-bounds access.

CVSS3: 6.3
nvd
3 дня назад

FreeRDP before 3.31.0 contains an integer overflow in the audin Apple backends when processing FramesPerPacket values from MSG_SNDIN_OPEN messages. Attackers can supply crafted FramesPerPacket values that cause AudioQueueAllocateBuffer size computation to wrap, resulting in undersized buffer allocation and potential out-of-bounds access.

CVSS3: 6.3
debian
3 дня назад

FreeRDP before 3.31.0 contains an integer overflow in the audin Apple ...

EPSS

Процентиль: 16%
0.00244
Низкий

5.3 Medium

CVSS4

6.3 Medium

CVSS3

Дефекты

CWE-131