Описание
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP's winpr/libwinpr/sspi/Kerberos/kerberos.c kerberos_DecryptMessage function fails to bound the peer-controlled GSS Wrap-token EC field before using it with RRC in IOV pointer offsets, allowing a malicious RDP peer to trigger out-of-bounds reads and in-place writes during CredSSP/NLA Kerberos decryption. This issue is fixed in version 3.30.0.
A flaw in FreeRDP's Kerberos implementation allows a malicious RDP peer to cause an out-of-bounds memory access by providing an unbounded GSS Wrap-token EC field. This occurs during CredSSP/NLA decryption and can lead to a denial of service or information disclosure.
Отчет
An Important out-of-bounds memory vulnerability in FreeRDP's CredSSP/NLA Kerberos decryption allows a malicious RDP endpoint to execute arbitrary code or expose sensitive information on connected clients and servers. This flaw only affects FreeRDP 3.0.0 and newer, meaning RHEL 9 and older versions are not affected.
Меры по смягчению последствий
Use FreeRDP with Kerberos/NLA only against trusted RDP peers. As a client, avoid connecting to untrusted RDP servers; as a server, restrict inbound RDP to trusted clients using host firewall rules or network segmentation.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | freerdp | Affected | ||
| Red Hat Enterprise Linux 6 | freerdp | Not affected | ||
| Red Hat Enterprise Linux 7 | freerdp | Not affected | ||
| Red Hat Enterprise Linux 8 | freerdp | Not affected | ||
| Red Hat Enterprise Linux 9 | freerdp | Not affected |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
6.4 Medium
CVSS3
Связанные уязвимости
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP's winpr/libwinpr/sspi/Kerberos/kerberos.c kerberos_DecryptMessage function fails to bound the peer-controlled GSS Wrap-token EC field before using it with RRC in IOV pointer offsets, allowing a malicious RDP peer to trigger out-of-bounds reads and in-place writes during CredSSP/NLA Kerberos decryption. This issue is fixed in version 3.30.0.
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP's winpr/libwinpr/sspi/Kerberos/kerberos.c kerberos_DecryptMessage function fails to bound the peer-controlled GSS Wrap-token EC field before using it with RRC in IOV pointer offsets, allowing a malicious RDP peer to trigger out-of-bounds reads and in-place writes during CredSSP/NLA Kerberos decryption. This issue is fixed in version 3.30.0.
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...
Уязвимость функции kerberos_DecryptMessage() файла winpr/libwinpr/sspi/Kerberos/kerberos.c RDP-клиента FreeRDP, позволяющая нарушителю раскрыть защищаемую информацию и вызвать отказ в обсуживании
EPSS
6.4 Medium
CVSS3