Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vg28-cmpq-3hp8

Опубликовано: 15 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7.7
CVSS3: 7.5

Описание

FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in server-side static virtual channel handling when CHANNEL_OPTION_SHOW_PROTOCOL is enabled. Authenticated clients can queue oversized channel messages that cause buffer underflow and corrupt heap memory including live pointers, potentially enabling code execution.

FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in server-side static virtual channel handling when CHANNEL_OPTION_SHOW_PROTOCOL is enabled. Authenticated clients can queue oversized channel messages that cause buffer underflow and corrupt heap memory including live pointers, potentially enabling code execution.

EPSS

Процентиль: 50%
0.00649
Низкий

7.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-191

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 дня назад

[GHSA-9jcm-x588-gh26: SHOW_PROTOCOL live-pointer overwrite]

CVSS3: 7.5
redhat
4 дня назад

FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in server-side static virtual channel handling when CHANNEL_OPTION_SHOW_PROTOCOL is enabled. Authenticated clients can queue oversized channel messages that cause buffer underflow and corrupt heap memory including live pointers, potentially enabling code execution.

CVSS3: 7.5
nvd
4 дня назад

FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in server-side static virtual channel handling when CHANNEL_OPTION_SHOW_PROTOCOL is enabled. Authenticated clients can queue oversized channel messages that cause buffer underflow and corrupt heap memory including live pointers, potentially enabling code execution.

CVSS3: 7.5
debian
4 дня назад

FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerab ...

EPSS

Процентиль: 50%
0.00649
Низкий

7.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-191