Описание
FreeRDP versions before 3.31.0 contain an information disclosure vulnerability in the RDPGFX server's ResetGraphics PDU serializer that fails to initialize padding bytes in the fixed 340-byte wire format. Attackers can receive uninitialized heap memory including live pointers and GLib function addresses transmitted in the PDU, defeating heap ASLR and disclosing the GLib module base address.
A flaw was found in FreeRDP. This information disclosure vulnerability exists in the RDPGFX server's ResetGraphics Protocol Data Unit (PDU) serializer. It fails to properly initialize padding bytes, allowing a remote attacker to receive uninitialized heap memory. This can lead to the disclosure of sensitive data, including live pointers and GLib function addresses, which could defeat Address Space Layout Randomization (ASLR) and reveal the GLib module's base address.
Меры по смягчению последствий
To mitigate this issue, restrict network access to FreeRDP server instances to only trusted clients and networks. Configure firewall rules to limit inbound connections to the RDP port (typically 3389) from untrusted sources. If FreeRDP server functionality is not required, consider disabling or uninstalling the FreeRDP server component.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | freerdp | Affected | ||
| Red Hat Enterprise Linux 6 | freerdp | Not affected | ||
| Red Hat Enterprise Linux 7 | freerdp | Affected | ||
| Red Hat Enterprise Linux 8 | freerdp | Affected | ||
| Red Hat Enterprise Linux 9 | freerdp | Affected |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
[GHSA-r7jx-j9h7-j4xj: FreeRDP RDPGFX ResetGraphics discloses up to 300 bytes of uninitialized heap memory]
FreeRDP versions before 3.31.0 contain an information disclosure vulnerability in the RDPGFX server's ResetGraphics PDU serializer that fails to initialize padding bytes in the fixed 340-byte wire format. Attackers can receive uninitialized heap memory including live pointers and GLib function addresses transmitted in the PDU, defeating heap ASLR and disclosing the GLib module base address.
FreeRDP versions before 3.31.0 contain an information disclosure vulne ...
FreeRDP versions before 3.31.0 contain an information disclosure vulnerability in the RDPGFX server's ResetGraphics PDU serializer that fails to initialize padding bytes in the fixed 340-byte wire format. Attackers can receive uninitialized heap memory including live pointers and GLib function addresses transmitted in the PDU, defeating heap ASLR and disclosing the GLib module base address.
EPSS
6.5 Medium
CVSS3