Описание
FreeRDP before 3.31.0 contains an out-of-bounds read vulnerability in the URBDRC channel's func_get_ep_desc function that indexes interface arrays by position instead of protocol field InterfaceNumber. A malicious RDP server can send a crafted SELECT_CONFIGURATION message with permuted InterfaceNumber values to read past allocated heap memory and crash the client.
A flaw was found in FreeRDP. A malicious Remote Desktop Protocol (RDP) server can exploit an out-of-bounds read vulnerability in the URBDRC (USB device redirection) channel. By sending a specially crafted message, the server can cause the FreeRDP client to read beyond its allocated memory, leading to a client crash and a denial of service.
Меры по смягчению последствий
To mitigate this issue, users should avoid connecting to untrusted or unverified RDP servers. Restricting FreeRDP client connections to known, trusted RDP servers can prevent exploitation of this vulnerability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | freerdp | Affected | ||
| Red Hat Enterprise Linux 6 | freerdp | Out of support scope | ||
| Red Hat Enterprise Linux 7 | freerdp | Affected | ||
| Red Hat Enterprise Linux 8 | freerdp | Affected | ||
| Red Hat Enterprise Linux 9 | freerdp | Affected |
Показывать по
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
[GHSA-hg4r-vv53-vwf8: URBDRC out-of-bounds read in func_get_ep_desc via InterfaceNumber/array-position index mismatch]
FreeRDP before 3.31.0 contains an out-of-bounds read vulnerability in the URBDRC channel's func_get_ep_desc function that indexes interface arrays by position instead of protocol field InterfaceNumber. A malicious RDP server can send a crafted SELECT_CONFIGURATION message with permuted InterfaceNumber values to read past allocated heap memory and crash the client.
FreeRDP before 3.31.0 contains an out-of-bounds read vulnerability in ...
FreeRDP before 3.31.0 contains an out-of-bounds read vulnerability in the URBDRC channel's func_get_ep_desc function that indexes interface arrays by position instead of protocol field InterfaceNumber. A malicious RDP server can send a crafted SELECT_CONFIGURATION message with permuted InterfaceNumber values to read past allocated heap memory and crash the client.
EPSS
6.5 Medium
CVSS3