Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2023-2326

Опубликовано: 15 мая 2023
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2023-2326: freerdp security update (MODERATE)

[2:2.4.1-5]

  • Fix 'implicit declaration of function' errors (#2136155, #2145140)

[- 2:2.4.1-4]

  • CVE-2022-39282: Fix length checks in parallel driver (#2136152)
  • CVE-2022-39283: Add missing length check in video channel (#2136154)
  • CVE-2022-39316, CVE-2022-39317: Add missing length checks in zgfx (#2145140)
  • CVE-2022-39318: Fix division by zero in urbdrc channel (#2145140)
  • CVE-2022-39319: Add missing length checks in urbdrc channel (#2145140)
  • CVE-2022-39320: Ensure urb_create_iocompletion uses size_t (#2145140)
  • CVE-2022-39347: Fix path validation in drive channel (#2145140)
  • CVE-2022-41877: Add missing length check in drive channel (#2145140)

Связанные уязвимости

oracle-oval
около 2 лет назад

ELSA-2023-2851: freerdp security update (MODERATE)

CVSS3: 9.1
redos
больше 2 лет назад

Множественные уязвимости FreeRDP

suse-cvrf
больше 2 лет назад

Security update for freerdp

suse-cvrf
больше 2 лет назад

Security update for freerdp

CVSS3: 4.8
ubuntu
больше 2 лет назад

FreeRDP is a free remote desktop protocol library and clients. In affected versions there is an out of bound read in ZGFX decoder component of FreeRDP. A malicious server can trick a FreeRDP based client to read out of bound data and try to decode it likely resulting in a crash. This issue has been addressed in the 2.9.0 release. Users are advised to upgrade.