Описание
FreeRDP before 3.31.0 contains a null pointer dereference vulnerability in gdi_surface_bits when processing Surface Bits commands with NSCodec codec ID. A malicious RDP server can crash a FreeRDP client by sending a crafted Surface Bits command claiming to use NSCodec, even when the codec is disabled.
A flaw was found in FreeRDP. A malicious Remote Desktop Protocol (RDP) server can trigger a null pointer dereference in the gdi_surface_bits function by sending a specially crafted Surface Bits command that claims to use the NSCodec codec ID. This vulnerability exists even when the NSCodec is disabled in the client. Successful exploitation allows a remote attacker to cause a FreeRDP client to crash, leading to a denial of service.
Меры по смягчению последствий
To mitigate this issue, users should avoid connecting to untrusted or unknown RDP servers with FreeRDP clients. This vulnerability requires a FreeRDP client to connect to a malicious RDP server to be exploited.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | freerdp | Affected | ||
| Red Hat Enterprise Linux 6 | freerdp | Out of support scope | ||
| Red Hat Enterprise Linux 7 | freerdp | Affected | ||
| Red Hat Enterprise Linux 8 | freerdp | Affected | ||
| Red Hat Enterprise Linux 9 | freerdp | Affected |
Показывать по
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
[GHSA-ffjr-p229-hpch: NULL pointer dereference in gdi_surface_bits when the client has not enabled NSCodec]
FreeRDP before 3.31.0 contains a null pointer dereference vulnerability in gdi_surface_bits when processing Surface Bits commands with NSCodec codec ID. A malicious RDP server can crash a FreeRDP client by sending a crafted Surface Bits command claiming to use NSCodec, even when the codec is disabled.
FreeRDP before 3.31.0 contains a null pointer dereference vulnerabilit ...
FreeRDP before 3.31.0 contains a null pointer dereference vulnerability in gdi_surface_bits when processing Surface Bits commands with NSCodec codec ID. A malicious RDP server can crash a FreeRDP client by sending a crafted Surface Bits command claiming to use NSCodec, even when the codec is disabled.
EPSS
6.5 Medium
CVSS3