Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-67290

Опубликовано: 01 авг. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

FreeRDP before 3.29.0 contains a heap out-of-bounds read vulnerability in the TSMF FFmpeg decoder when parsing AVC1 MPEG2VIDEOINFO media types with insufficient ExtraData. Attackers can send malformed media format data from a server to trigger a crash by reading fixed offsets without validating source buffer length.

A flaw was found in FreeRDP. A malicious Remote Desktop Protocol (RDP) server can send specially crafted media data to a connected client. This malformed data can trigger a heap out-of-bounds read vulnerability within the TSMF FFmpeg decoder, leading to the client application crashing. This can result in a denial of service for the client.

Отчет

This vulnerability in FreeRDP is rated as Important. A FreeRDP client connecting to a malicious or untrusted RDP server can be subjected to a denial of service. The flaw stems from a heap out-of-bounds read within the TSMF FFmpeg decoder when processing malformed media data, leading to client application crashes.

Меры по смягчению последствий

To mitigate this issue, disable the Terminal Services Multimedia Redirection (TSMF) feature when connecting to untrusted RDP servers. This prevents the vulnerable media processing from being engaged. For xfreerdp clients, use the /disable-tsmf or /tsmf:off command-line option: xfreerdp /disable-tsmf <server_address> Disabling TSMF will prevent multimedia content from being redirected during the RDP session.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10freerdpAffected
Red Hat Enterprise Linux 6freerdpOut of support scope
Red Hat Enterprise Linux 7freerdpAffected
Red Hat Enterprise Linux 8freerdpNot affected
Red Hat Enterprise Linux 9freerdpAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2509984FreeRDP: FreeRDP: Denial of Service via malformed media data

EPSS

Процентиль: 36%
0.00426
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 1 месяца назад

FreeRDP before 3.29.0 contains a heap out-of-bounds read vulnerability in the TSMF FFmpeg decoder when parsing AVC1 MPEG2VIDEOINFO media types with insufficient ExtraData. Attackers can send malformed media format data from a server to trigger a crash by reading fixed offsets without validating source buffer length.

CVSS3: 7.5
nvd
около 1 месяца назад

FreeRDP before 3.29.0 contains a heap out-of-bounds read vulnerability in the TSMF FFmpeg decoder when parsing AVC1 MPEG2VIDEOINFO media types with insufficient ExtraData. Attackers can send malformed media format data from a server to trigger a crash by reading fixed offsets without validating source buffer length.

CVSS3: 7.5
debian
около 1 месяца назад

FreeRDP before 3.29.0 contains a heap out-of-bounds read vulnerability ...

CVSS3: 7.5
github
около 1 месяца назад

FreeRDP before 3.29.0 contains a heap out-of-bounds read vulnerability in the TSMF FFmpeg decoder when parsing AVC1 MPEG2VIDEOINFO media types with insufficient ExtraData. Attackers can send malformed media format data from a server to trigger a crash by reading fixed offsets without validating source buffer length.

CVSS3: 7.5
fstec
около 2 месяцев назад

Уязвимость декодера TSMF FFmpeg RDP-клиента FreeRDP, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 36%
0.00426
Низкий

6.5 Medium

CVSS3