Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-67293

Опубликовано: 01 авг. 2026
Источник: redhat
CVSS3: 4.2
EPSS Низкий

Описание

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains an improper certificate hostname validation vulnerability. The TLS hostname matcher (tls_match_hostname() in libfreerdp/crypto/tls.c) treats a wildcard pattern such as *.example.com as matching any hostname ending in .example.com, so it incorrectly accepts a wildcard certificate for multi-label subdomains like a.b.example.com (which OpenSSL's X509_check_host() rejects). This weakens TLS server authentication under wildcard-certificate conditions.

A flaw was found in FreeRDP, a free implementation of the Remote Desktop Protocol (RDP). The software's Transport Layer Security (TLS) hostname matcher incorrectly validates wildcard certificates, allowing it to accept certificates for multi-label subdomains that should not be covered. This vulnerability could enable a remote attacker to impersonate a legitimate server, potentially compromising the authenticity of the connection. This weakens the overall security of TLS server authentication.

Отчет

This Moderate flaw in FreeRDP weakens TLS server authentication by incorrectly validating wildcard certificates. The client's TLS hostname matcher accepts multi-label subdomains (e.g., a.b.example.com) for a single-level wildcard (e.g., *.example.com), which deviates from standard OpenSSL behavior. This could allow a malicious RDP server to impersonate a legitimate server if a client attempts to connect to a subdomain covered by an improperly validated wildcard certificate.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10freerdpFix deferred
Red Hat Enterprise Linux 6freerdpOut of support scope
Red Hat Enterprise Linux 7freerdpOut of support scope
Red Hat Enterprise Linux 8freerdpFix deferred
Red Hat Enterprise Linux 9freerdpFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-295
https://bugzilla.redhat.com/show_bug.cgi?id=2510015FreeRDP: FreeRDP: Weakens TLS server authentication due to improper wildcard certificate hostname validation

EPSS

Процентиль: 6%
0.00166
Низкий

4.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.2
ubuntu
около 1 месяца назад

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains an improper certificate hostname validation vulnerability. The TLS hostname matcher (tls_match_hostname() in libfreerdp/crypto/tls.c) treats a wildcard pattern such as *.example.com as matching any hostname ending in .example.com, so it incorrectly accepts a wildcard certificate for multi-label subdomains like a.b.example.com (which OpenSSL's X509_check_host() rejects). This weakens TLS server authentication under wildcard-certificate conditions.

CVSS3: 4.2
nvd
около 1 месяца назад

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains an improper certificate hostname validation vulnerability. The TLS hostname matcher (tls_match_hostname() in libfreerdp/crypto/tls.c) treats a wildcard pattern such as *.example.com as matching any hostname ending in .example.com, so it incorrectly accepts a wildcard certificate for multi-label subdomains like a.b.example.com (which OpenSSL's X509_check_host() rejects). This weakens TLS server authentication under wildcard-certificate conditions.

CVSS3: 4.2
debian
около 1 месяца назад

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains an improp ...

CVSS3: 4.2
github
около 1 месяца назад

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains an improper certificate hostname validation vulnerability. The TLS hostname matcher (tls_match_hostname() in libfreerdp/crypto/tls.c) treats a wildcard pattern such as *.example.com as matching any hostname ending in .example.com, so it incorrectly accepts a wildcard certificate for multi-label subdomains like a.b.example.com (which OpenSSL's X509_check_host() rejects). This weakens TLS server authentication under wildcard-certificate conditions.

CVSS3: 9.1
fstec
около 2 месяцев назад

Уязвимость функции tls_match_hostname() файла libfreerdp/crypto/tls.c RDP-клиента FreeRDP, позволяющая нарушителю подменить RDP-сервер

EPSS

Процентиль: 6%
0.00166
Низкий

4.2 Medium

CVSS3