Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mj63-24h6-p8wq

Опубликовано: 02 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7.7
CVSS3: 7.5

Описание

FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES backends that fail to validate the FramesPerPacket parameter from RDP servers. Attackers can supply a malicious FramesPerPacket value causing allocation size wraparound, resulting in heap-based buffer overflow on ALSA or denial of service on all platforms.

FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES backends that fail to validate the FramesPerPacket parameter from RDP servers. Attackers can supply a malicious FramesPerPacket value causing allocation size wraparound, resulting in heap-based buffer overflow on ALSA or denial of service on all platforms.

7.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-122

Связанные уязвимости

debian

Описание отсутствует

7.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-122