Описание
FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in server-side static virtual channel handling when CHANNEL_OPTION_SHOW_PROTOCOL is enabled. Authenticated clients can queue oversized channel messages that cause buffer underflow and corrupt heap memory including live pointers, potentially enabling code execution.
A flaw was found in FreeRDP. An authenticated client can send specially crafted, oversized messages to the server when the CHANNEL_OPTION_SHOW_PROTOCOL feature is active. This can cause a buffer underflow, leading to corruption of memory and potentially allowing an attacker to execute malicious code on the server.
Меры по смягчению последствий
To mitigate this issue, restrict network access to the FreeRDP server to only trusted clients or localhost. This can be achieved by configuring firewall rules to limit inbound connections to the FreeRDP service port. A restart of the FreeRDP server may be required for network configuration changes to take effect.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | freerdp | Affected | ||
| Red Hat Enterprise Linux 6 | freerdp | Not affected | ||
| Red Hat Enterprise Linux 7 | freerdp | Not affected | ||
| Red Hat Enterprise Linux 8 | freerdp | Not affected | ||
| Red Hat Enterprise Linux 9 | freerdp | Not affected |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
[GHSA-9jcm-x588-gh26: SHOW_PROTOCOL live-pointer overwrite]
FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in server-side static virtual channel handling when CHANNEL_OPTION_SHOW_PROTOCOL is enabled. Authenticated clients can queue oversized channel messages that cause buffer underflow and corrupt heap memory including live pointers, potentially enabling code execution.
FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerab ...
FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in server-side static virtual channel handling when CHANNEL_OPTION_SHOW_PROTOCOL is enabled. Authenticated clients can queue oversized channel messages that cause buffer underflow and corrupt heap memory including live pointers, potentially enabling code execution.
7.5 High
CVSS3