Описание
FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses in http_response_recv_body(). Attackers controlling a malicious RD Gateway endpoint can send oversized chunked response bodies to exhaust client memory resources without triggering the configured size limit.
A vulnerability in FreeRDP allows a malicious RD Gateway to bypass client-side size limits by sending oversized chunked HTTP responses. This exhausts the client's memory, resulting in a Denial of Service (DoS).
Отчет
A Moderate vulnerability in FreeRDP 3.x allows a malicious or compromised Remote Desktop Gateway to exhaust client memory by sending oversized chunked HTTP responses that bypass the 64 MiB size cap. This flaw affects FreeRDP 3.x clients connecting to untrusted endpoints; RHEL 9 and older releases ship earlier FreeRDP versions that lack this code path and are not affected.
Меры по смягчению последствий
To mitigate this issue, FreeRDP clients should only connect to trusted Remote Desktop Gateway endpoints. Avoiding connections to untrusted or potentially compromised gateways will prevent exposure to malicious servers that could exploit this vulnerability by sending oversized chunked HTTP responses.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | freerdp | Affected | ||
| Red Hat Enterprise Linux 6 | freerdp | Not affected | ||
| Red Hat Enterprise Linux 7 | freerdp | Not affected | ||
| Red Hat Enterprise Linux 8 | freerdp | Not affected | ||
| Red Hat Enterprise Linux 9 | freerdp | Not affected |
Показывать по
Дополнительная информация
Статус:
6.5 Medium
CVSS3
Связанные уязвимости
FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses in http_response_recv_body(). Attackers controlling a malicious RD Gateway endpoint can send oversized chunked response bodies to exhaust client memory resources without triggering the configured size limit.
FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses in http_response_recv_body(). Attackers controlling a malicious RD Gateway endpoint can send oversized chunked response bodies to exhaust client memory resources without triggering the configured size limit.
FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when pr ...
FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses in http_response_recv_body(). Attackers controlling a malicious RD Gateway endpoint can send oversized chunked response bodies to exhaust client memory resources without triggering the configured size limit.
Уязвимость функции http_response_recv_body() файла libfreerdp/core/gateway/http.c RDP-клиента FreeRDP, позволяющая нарушителю вызвать отказ в обслуживании
6.5 Medium
CVSS3