Описание
FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client's ServerHostname and, when the client connects through an HTTP proxy, is written directly into the proxy CONNECT request line and Host header by http_proxy_connect() without filtering. A malicious or compromised RDP server can send a crafted redirection PDU containing embedded control characters to inject arbitrary headers/requests into the HTTP proxy CONNECT request.
A flaw was found in FreeRDP. A malicious or compromised Remote Desktop Protocol (RDP) server can exploit this vulnerability to inject arbitrary headers or requests into an HTTP proxy CONNECT request. This occurs because FreeRDP does not properly validate control characters in the server-controlled RDP redirection TargetNetAddress field, which is then used without filtering. This injection could allow an attacker to manipulate the proxy's behavior or bypass certain network security policies.
Отчет
Moderate: This client-side vulnerability in FreeRDP allows for HTTP proxy request injection. Exploitation requires a FreeRDP client to be configured to use an HTTP proxy and to connect to a malicious or compromised RDP server, which then sends a crafted redirection PDU. This limits the attack surface to specific client configurations and interactions with untrusted RDP endpoints.
Меры по смягчению последствий
To mitigate this issue, FreeRDP clients should avoid connecting to untrusted RDP servers when configured to use an HTTP proxy. Alternatively, if connecting to potentially untrusted RDP servers, disable the HTTP proxy configuration for FreeRDP.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | freerdp | Out of support scope | ||
| Red Hat Enterprise Linux 7 | freerdp | Affected | ||
| Red Hat Enterprise Linux 10 | freerdp | Fixed | RHSA-2026:54486 | 13.08.2026 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | freerdp | Fixed | RHSA-2026:58711 | 24.08.2026 |
| Red Hat Enterprise Linux 8 | freerdp | Fixed | RHSA-2026:54485 | 13.08.2026 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | freerdp | Fixed | RHSA-2026:60173 | 26.08.2026 |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | freerdp | Fixed | RHSA-2026:60173 | 26.08.2026 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | freerdp | Fixed | RHSA-2026:61250 | 31.08.2026 |
| Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On | freerdp | Fixed | RHSA-2026:61250 | 31.08.2026 |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | freerdp | Fixed | RHSA-2026:61251 | 31.08.2026 |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
5 Medium
CVSS3
Связанные уязвимости
FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client's ServerHostname and, when the client connects through an HTTP proxy, is written directly into the proxy CONNECT request line and Host header by http_proxy_connect() without filtering. A malicious or compromised RDP server can send a crafted redirection PDU containing embedded control characters to inject arbitrary headers/requests into the HTTP proxy CONNECT request.
FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client's ServerHostname and, when the client connects through an HTTP proxy, is written directly into the proxy CONNECT request line and Host header by http_proxy_connect() without filtering. A malicious or compromised RDP server can send a crafted redirection PDU containing embedded control characters to inject arbitrary headers/requests into the HTTP proxy CONNECT request.
FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate ...
FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client's ServerHostname and, when the client connects through an HTTP proxy, is written directly into the proxy CONNECT request line and Host header by http_proxy_connect() without filtering. A malicious or compromised RDP server can send a crafted redirection PDU containing embedded control characters to inject arbitrary headers/requests into the HTTP proxy CONNECT request.
Уязвимость функции http_proxy_connect() RDP-клиента FreeRDP, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации
EPSS
5 Medium
CVSS3