Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xxh7-m6m8-7839

Опубликовано: 03 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.3
CVSS3: 5.4

Описание

FreeRDP before 3.31.0 contains a heap out-of-bounds read vulnerability in the general_ChromaV1ToYUV444 function during AVC444 chroma plane reconstruction. A malicious RDP server can craft a RFX_AVC444_BITMAP_STREAM with specific frame geometry to trigger an out-of-bounds memory read past the allocated luma plane.

FreeRDP before 3.31.0 contains a heap out-of-bounds read vulnerability in the general_ChromaV1ToYUV444 function during AVC444 chroma plane reconstruction. A malicious RDP server can craft a RFX_AVC444_BITMAP_STREAM with specific frame geometry to trigger an out-of-bounds memory read past the allocated luma plane.

EPSS

Процентиль: 24%
0.00314
Низкий

5.3 Medium

CVSS4

5.4 Medium

CVSS3

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 5.4
ubuntu
12 дней назад

FreeRDP before 3.31.0 contains a heap out-of-bounds read vulnerability in the general_ChromaV1ToYUV444 function during AVC444 chroma plane reconstruction. A malicious RDP server can craft a RFX_AVC444_BITMAP_STREAM with specific frame geometry to trigger an out-of-bounds memory read past the allocated luma plane.

CVSS3: 5.4
redhat
13 дней назад

FreeRDP before 3.31.0 contains a heap out-of-bounds read vulnerability in the general_ChromaV1ToYUV444 function during AVC444 chroma plane reconstruction. A malicious RDP server can craft a RFX_AVC444_BITMAP_STREAM with specific frame geometry to trigger an out-of-bounds memory read past the allocated luma plane.

CVSS3: 5.4
nvd
13 дней назад

FreeRDP before 3.31.0 contains a heap out-of-bounds read vulnerability in the general_ChromaV1ToYUV444 function during AVC444 chroma plane reconstruction. A malicious RDP server can craft a RFX_AVC444_BITMAP_STREAM with specific frame geometry to trigger an out-of-bounds memory read past the allocated luma plane.

CVSS3: 5.4
debian
13 дней назад

FreeRDP before 3.31.0 contains a heap out-of-bounds read vulnerability ...

EPSS

Процентиль: 24%
0.00314
Низкий

5.3 Medium

CVSS4

5.4 Medium

CVSS3

Дефекты

CWE-125