Описание
FreeRDP before 3.31.0 contains an integer overflow in the audin Apple backends when processing FramesPerPacket values from MSG_SNDIN_OPEN messages. Attackers can supply crafted FramesPerPacket values that cause AudioQueueAllocateBuffer size computation to wrap, resulting in undersized buffer allocation and potential out-of-bounds access.
A flaw was found in FreeRDP. An integer overflow in the audin Apple backends, specifically when processing FramesPerPacket values from MSG_SNDIN_OPEN messages, allows a malicious RDP (Remote Desktop Protocol) server to supply crafted values. This can cause the AudioQueueAllocateBuffer size computation to wrap, leading to an undersized buffer allocation and potential out-of-bounds access. This memory safety issue could result in information disclosure, denial of service, or potentially arbitrary code execution.
Меры по смягчению последствий
To mitigate this issue, ensure that FreeRDP is not configured to use the audin Apple backends. This specific functionality is not typically enabled by default in Red Hat Enterprise Linux environments. If FreeRDP is used to connect to macOS systems and audio input redirection is enabled, consider disabling this feature or restricting connections to trusted remote desktop servers.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | freerdp | Fix deferred | ||
| Red Hat Enterprise Linux 6 | freerdp | Out of support scope | ||
| Red Hat Enterprise Linux 7 | freerdp | Fix deferred | ||
| Red Hat Enterprise Linux 8 | freerdp | Fix deferred | ||
| Red Hat Enterprise Linux 9 | freerdp | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
6.3 Medium
CVSS3
Связанные уязвимости
[GHSA-f5p6-88mh-59vg: audin Apple backends perform overflow-prone buffer size arithmetic from server-controlled values]
FreeRDP before 3.31.0 contains an integer overflow in the audin Apple backends when processing FramesPerPacket values from MSG_SNDIN_OPEN messages. Attackers can supply crafted FramesPerPacket values that cause AudioQueueAllocateBuffer size computation to wrap, resulting in undersized buffer allocation and potential out-of-bounds access.
FreeRDP before 3.31.0 contains an integer overflow in the audin Apple ...
FreeRDP before 3.31.0 contains an integer overflow in the audin Apple backends when processing FramesPerPacket values from MSG_SNDIN_OPEN messages. Attackers can supply crafted FramesPerPacket values that cause AudioQueueAllocateBuffer size computation to wrap, resulting in undersized buffer allocation and potential out-of-bounds access.
EPSS
6.3 Medium
CVSS3