Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-54486

Опубликовано: 13 авг. 2026
Источник: oracle-oval
Платформа: Oracle Linux 10

Описание

ELSA-2026-54486: freerdp security update (IMPORTANT)

[2:3.10.3-12.8]

  • Backport several CVE fixes (CVE-2026-64620, CVE-2026-64621, CVE-2026-64624, CVE-2026-67289, CVE-2026-67299, CVE-2026-68580) Resolves: RHEL-212621, RHEL-212978, RHEL-213168, RHEL-222783, RHEL-222983, Resolves: RHEL-223604

Обновленные пакеты

Oracle Linux 10

Oracle Linux aarch64

freerdp

3.10.3-12.el10_2.8

freerdp-devel

3.10.3-12.el10_2.8

freerdp-libs

3.10.3-12.el10_2.8

freerdp-server

3.10.3-12.el10_2.8

libwinpr

3.10.3-12.el10_2.8

libwinpr-devel

3.10.3-12.el10_2.8

Oracle Linux x86_64

freerdp

3.10.3-12.el10_2.8

freerdp-devel

3.10.3-12.el10_2.8

freerdp-libs

3.10.3-12.el10_2.8

freerdp-server

3.10.3-12.el10_2.8

libwinpr

3.10.3-12.el10_2.8

libwinpr-devel

3.10.3-12.el10_2.8

Связанные уязвимости

rocky
19 дней назад

Important: freerdp security update

CVSS3: 9.8
ubuntu
около 1 месяца назад

FreeRDP before 3.28.0 (affected <=3.27.1) contains a heap-based buffer overflow in crypto_rsa_common() (libfreerdp/crypto/crypto.c). The function writes the modular-exponentiation result into the caller's output buffer via BN_bn2bin() and only afterward checks output_length > out_length, so out-of-bounds bytes are written before the bounds check. On the server side, when a client selects RDP Standard Security, the encrypted client random is decrypted into a fixed 32-byte buffer. Because the server publishes its RSA public key, an unauthenticated attacker can forge a ciphertext whose decrypted value is up to the full modulus length (e.g. 256 bytes for RSA-2048), overflowing the 32-byte heap buffer by up to ~224 attacker-controlled bytes pre-authentication, resulting in denial of service.

CVSS3: 8.1
redhat
около 1 месяца назад

FreeRDP before 3.28.0 (affected <=3.27.1) contains a heap-based buffer overflow in crypto_rsa_common() (libfreerdp/crypto/crypto.c). The function writes the modular-exponentiation result into the caller's output buffer via BN_bn2bin() and only afterward checks output_length > out_length, so out-of-bounds bytes are written before the bounds check. On the server side, when a client selects RDP Standard Security, the encrypted client random is decrypted into a fixed 32-byte buffer. Because the server publishes its RSA public key, an unauthenticated attacker can forge a ciphertext whose decrypted value is up to the full modulus length (e.g. 256 bytes for RSA-2048), overflowing the 32-byte heap buffer by up to ~224 attacker-controlled bytes pre-authentication, resulting in denial of service.

CVSS3: 9.8
nvd
около 1 месяца назад

FreeRDP before 3.28.0 (affected <=3.27.1) contains a heap-based buffer overflow in crypto_rsa_common() (libfreerdp/crypto/crypto.c). The function writes the modular-exponentiation result into the caller's output buffer via BN_bn2bin() and only afterward checks output_length > out_length, so out-of-bounds bytes are written before the bounds check. On the server side, when a client selects RDP Standard Security, the encrypted client random is decrypted into a fixed 32-byte buffer. Because the server publishes its RSA public key, an unauthenticated attacker can forge a ciphertext whose decrypted value is up to the full modulus length (e.g. 256 bytes for RSA-2048), overflowing the 32-byte heap buffer by up to ~224 attacker-controlled bytes pre-authentication, resulting in denial of service.

CVSS3: 9.8
debian
около 1 месяца назад

FreeRDP before 3.28.0 (affected <=3.27.1) contains a heap-based buffer ...