Описание
FreeRDP before 3.29.0 contains a heap out-of-bounds read vulnerability in the TSMF FFmpeg decoder when parsing AVC1 MPEG2VIDEOINFO media types with insufficient ExtraData. Attackers can send malformed media format data from a server to trigger a crash by reading fixed offsets without validating source buffer length.
A flaw was found in FreeRDP. A malicious Remote Desktop Protocol (RDP) server can send specially crafted media data to a connected client. This malformed data can trigger a heap out-of-bounds read vulnerability within the TSMF FFmpeg decoder, leading to the client application crashing. This can result in a denial of service for the client.
Отчет
This vulnerability in FreeRDP is rated as Important. A FreeRDP client connecting to a malicious or untrusted RDP server can be subjected to a denial of service. The flaw stems from a heap out-of-bounds read within the TSMF FFmpeg decoder when processing malformed media data, leading to client application crashes.
Меры по смягчению последствий
To mitigate this issue, disable the Terminal Services Multimedia Redirection (TSMF) feature when connecting to untrusted RDP servers. This prevents the vulnerable media processing from being engaged.
For xfreerdp clients, use the /disable-tsmf or /tsmf:off command-line option:
xfreerdp /disable-tsmf <server_address>
Disabling TSMF will prevent multimedia content from being redirected during the RDP session.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | freerdp | Affected | ||
| Red Hat Enterprise Linux 6 | freerdp | Out of support scope | ||
| Red Hat Enterprise Linux 7 | freerdp | Affected | ||
| Red Hat Enterprise Linux 8 | freerdp | Not affected | ||
| Red Hat Enterprise Linux 9 | freerdp | Affected |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
FreeRDP before 3.29.0 contains a heap out-of-bounds read vulnerability in the TSMF FFmpeg decoder when parsing AVC1 MPEG2VIDEOINFO media types with insufficient ExtraData. Attackers can send malformed media format data from a server to trigger a crash by reading fixed offsets without validating source buffer length.
FreeRDP before 3.29.0 contains a heap out-of-bounds read vulnerability in the TSMF FFmpeg decoder when parsing AVC1 MPEG2VIDEOINFO media types with insufficient ExtraData. Attackers can send malformed media format data from a server to trigger a crash by reading fixed offsets without validating source buffer length.
FreeRDP before 3.29.0 contains a heap out-of-bounds read vulnerability ...
FreeRDP before 3.29.0 contains a heap out-of-bounds read vulnerability in the TSMF FFmpeg decoder when parsing AVC1 MPEG2VIDEOINFO media types with insufficient ExtraData. Attackers can send malformed media format data from a server to trigger a crash by reading fixed offsets without validating source buffer length.
Уязвимость декодера TSMF FFmpeg RDP-клиента FreeRDP, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
6.5 Medium
CVSS3