Описание
FreeRDP before 3.31.0 contains an out-of-bounds read vulnerability in the rdpdr_dump_packet function due to 32-bit unsigned integer wraparound in buffer bounds validation. A malicious RDP server can send a crafted RDPDR packet with computerNameLen set to 0xFFFFFFF0 to bypass bounds checks and trigger memory reads past the packet buffer, causing client crashes or heap disclosure in logs.
A flaw was found in FreeRDP, where an out-of-bounds read vulnerability exists in the rdpdr_dump_packet function. This is due to a 32-bit unsigned integer wraparound during buffer bounds validation. A malicious RDP server can send a specially crafted RDPDR packet, bypassing security checks and causing the client to read memory beyond the intended buffer. This can result in client crashes, leading to a denial of service, or the disclosure of sensitive heap memory information in logs. Exploitation requires the client to have WLOG_TRACE-level logging enabled.
Меры по смягчению последствий
To mitigate this issue, users should avoid connecting to untrusted or potentially malicious RDP servers. Restricting FreeRDP client connections to only known and trusted RDP servers significantly reduces the attack surface. If connecting to untrusted servers is unavoidable, consider using a highly isolated environment for the client.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | freerdp | Affected | ||
| Red Hat Enterprise Linux 6 | freerdp | Out of support scope | ||
| Red Hat Enterprise Linux 7 | freerdp | Affected | ||
| Red Hat Enterprise Linux 8 | freerdp | Affected | ||
| Red Hat Enterprise Linux 9 | freerdp | Affected |
Показывать по
Дополнительная информация
Статус:
EPSS
7.1 High
CVSS3
Связанные уязвимости
[GHSA-c5gr-hmqp-pwj4: RDPDR out-of-bounds read in rdpdr_dump_packet via UINT32 wraparound in 16 + computerNameLen guard]
FreeRDP before 3.31.0 contains an out-of-bounds read vulnerability in the rdpdr_dump_packet function due to 32-bit unsigned integer wraparound in buffer bounds validation. A malicious RDP server can send a crafted RDPDR packet with computerNameLen set to 0xFFFFFFF0 to bypass bounds checks and trigger memory reads past the packet buffer, causing client crashes or heap disclosure in logs.
FreeRDP before 3.31.0 contains an out-of-bounds read vulnerability in ...
FreeRDP before 3.31.0 contains an out-of-bounds read vulnerability in the rdpdr_dump_packet function due to 32-bit unsigned integer wraparound in buffer bounds validation. A malicious RDP server can send a crafted RDPDR packet with computerNameLen set to 0xFFFFFFF0 to bypass bounds checks and trigger memory reads past the packet buffer, causing client crashes or heap disclosure in logs.
EPSS
7.1 High
CVSS3