Описание
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versions are subject to an Out-Of-Bounds Write in the progressive_decompress
function. This issue is likely down to incorrect calculations of the nXSrc
and nYSrc
variables. This issue has been addressed in versions 2.11.0 and 3.0.0-beta3. Users are advised to upgrade. there are no known workarounds for this vulnerability.
A flaw was found in FreeRDP. Incorrect calculations in the progressive_decompress
function may allow for a buffer overflow, resulting in a crash.
Отчет
Only FreeRDP based clients are affected. FreeRDP proxy is not affected as image decoding is not done by proxy.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 6 | freerdp | Out of support scope | ||
Red Hat Enterprise Linux 7 | freerdp | Out of support scope | ||
Red Hat Enterprise Linux 8 | freerdp | Will not fix | ||
Red Hat Enterprise Linux 9 | freerdp | Fixed | RHSA-2024:2208 | 30.04.2024 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versions are subject to an Out-Of-Bounds Write in the `progressive_decompress` function. This issue is likely down to incorrect calculations of the `nXSrc` and `nYSrc` variables. This issue has been addressed in versions 2.11.0 and 3.0.0-beta3. Users are advised to upgrade. there are no known workarounds for this vulnerability.
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versions are subject to an Out-Of-Bounds Write in the `progressive_decompress` function. This issue is likely down to incorrect calculations of the `nXSrc` and `nYSrc` variables. This issue has been addressed in versions 2.11.0 and 3.0.0-beta3. Users are advised to upgrade. there are no known workarounds for this vulnerability.
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), ...
Уязвимость функции progressive_decompress() RDP-клиента FreeRDP, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
7.5 High
CVSS3