Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7w2c-f8mf-gfr7

Опубликовано: 15 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7.1
CVSS3: 6.5

Описание

FreeRDP versions before 3.31.0 contain an integer overflow in WinPR's Stream_EnsureRemainingCapacity function that allows remote attackers to cause denial of service. A malicious RD Gateway peer can send a WebSocket Ping frame with a crafted 64-bit extended payload length to trigger integer wraparound, resulting in a double free that crashes the FreeRDP client during connection.

FreeRDP versions before 3.31.0 contain an integer overflow in WinPR's Stream_EnsureRemainingCapacity function that allows remote attackers to cause denial of service. A malicious RD Gateway peer can send a WebSocket Ping frame with a crafted 64-bit extended payload length to trigger integer wraparound, resulting in a double free that crashes the FreeRDP client during connection.

EPSS

Процентиль: 38%
0.00442
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-190

Связанные уязвимости

CVSS3: 6.5
ubuntu
3 дня назад

[GHSA-vccg-35r5-8jrf: Stream_EnsureCapacity still overflows]

CVSS3: 6.5
redhat
3 дня назад

FreeRDP versions before 3.31.0 contain an integer overflow in WinPR's Stream_EnsureRemainingCapacity function that allows remote attackers to cause denial of service. A malicious RD Gateway peer can send a WebSocket Ping frame with a crafted 64-bit extended payload length to trigger integer wraparound, resulting in a double free that crashes the FreeRDP client during connection.

CVSS3: 6.5
nvd
3 дня назад

FreeRDP versions before 3.31.0 contain an integer overflow in WinPR's Stream_EnsureRemainingCapacity function that allows remote attackers to cause denial of service. A malicious RD Gateway peer can send a WebSocket Ping frame with a crafted 64-bit extended payload length to trigger integer wraparound, resulting in a double free that crashes the FreeRDP client during connection.

CVSS3: 6.5
debian
3 дня назад

FreeRDP versions before 3.31.0 contain an integer overflow in WinPR's ...

EPSS

Процентиль: 38%
0.00442
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-190