Описание
FreeRDP versions before 3.31.0 contain a heap-based buffer overflow in nego_send_negotiation_request when processing Server Redirection PDU messages with attacker-controlled LoadBalanceInfo fields. A malicious RDP server can trigger the overflow by sending an arbitrary-length field that gets written to a fixed 512-byte buffer without validation, causing client crashes or potential code execution when chained with memory disclosure.
A flaw was found in FreeRDP. A malicious Remote Desktop Protocol (RDP) server can exploit a heap-based buffer overflow vulnerability in the nego_send_negotiation_request function. By sending a specially crafted Server Redirection PDU message with an attacker-controlled LoadBalanceInfo field, the server can write an arbitrary-length field into a fixed-size buffer without proper validation. This can lead to a denial of service (client crash) or, when chained with a memory disclosure vulnerability, potentially remote code execution on the client system.
Меры по смягчению последствий
Users of FreeRDP clients should avoid connecting to untrusted or unknown RDP servers. This operational control reduces the risk of exploitation, as a malicious server is required to trigger the heap-based buffer overflow.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | freerdp | Affected | ||
| Red Hat Enterprise Linux 6 | freerdp | Out of support scope | ||
| Red Hat Enterprise Linux 7 | freerdp | Affected | ||
| Red Hat Enterprise Linux 8 | freerdp | Affected | ||
| Red Hat Enterprise Linux 9 | freerdp | Affected |
Показывать по
Дополнительная информация
Статус:
EPSS
8.8 High
CVSS3
Связанные уязвимости
[GHSA-2vf2-grvj-6g8x: Heap buffer overflow in nego_send_negotiation_request]
FreeRDP versions before 3.31.0 contain a heap-based buffer overflow in nego_send_negotiation_request when processing Server Redirection PDU messages with attacker-controlled LoadBalanceInfo fields. A malicious RDP server can trigger the overflow by sending an arbitrary-length field that gets written to a fixed 512-byte buffer without validation, causing client crashes or potential code execution when chained with memory disclosure.
FreeRDP versions before 3.31.0 contain a heap-based buffer overflow in ...
FreeRDP versions before 3.31.0 contain a heap-based buffer overflow in nego_send_negotiation_request when processing Server Redirection PDU messages with attacker-controlled LoadBalanceInfo fields. A malicious RDP server can trigger the overflow by sending an arbitrary-length field that gets written to a fixed 512-byte buffer without validation, causing client crashes or potential code execution when chained with memory disclosure.
EPSS
8.8 High
CVSS3