Описание
FreeRDP versions before 3.31.0 fail to validate MonitorIds array values when parsing RDP connection files, allowing unbounded array indexing in xf_detect_monitors. Attackers can craft a malicious RDP file with an out-of-range selectedmonitors value to trigger out-of-bounds heap read and write operations when opened in xfreerdp.
A flaw was found in FreeRDP. This vulnerability allows a remote attacker to trigger out-of-bounds memory access by crafting a malicious Remote Desktop Protocol (RDP) connection file. When a user opens this file, the FreeRDP client fails to properly validate array values, leading to a heap buffer overflow. This can result in a denial of service, causing the application to crash, and potentially lead to information disclosure or arbitrary code execution.
Меры по смягчению последствий
To mitigate this issue, users should exercise caution and avoid opening RDP connection files from untrusted or unknown sources. This vulnerability requires user interaction with a malicious file to be exploited.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | freerdp | Fix deferred | ||
| Red Hat Enterprise Linux 6 | freerdp | Not affected | ||
| Red Hat Enterprise Linux 7 | freerdp | Not affected | ||
| Red Hat Enterprise Linux 8 | freerdp | Not affected | ||
| Red Hat Enterprise Linux 9 | freerdp | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
6.6 Medium
CVSS3
Связанные уязвимости
[GHSA-23pf-q83q-x45r: Unbounded MonitorIds used as an array index in X11 monitor selection]
FreeRDP versions before 3.31.0 fail to validate MonitorIds array values when parsing RDP connection files, allowing unbounded array indexing in xf_detect_monitors. Attackers can craft a malicious RDP file with an out-of-range selectedmonitors value to trigger out-of-bounds heap read and write operations when opened in xfreerdp.
FreeRDP versions before 3.31.0 fail to validate MonitorIds array value ...
FreeRDP versions before 3.31.0 fail to validate MonitorIds array values when parsing RDP connection files, allowing unbounded array indexing in xf_detect_monitors. Attackers can craft a malicious RDP file with an out-of-range selectedmonitors value to trigger out-of-bounds heap read and write operations when opened in xfreerdp.
EPSS
6.6 Medium
CVSS3