Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2022:2354-1

Опубликовано: 11 июл. 2022
Источник: suse-cvrf

Описание

Security update for freerdp

This update for freerdp fixes the following issues:

  • CVE-2022-24882: Fixed incorrect check parameters in NTLM (bsc#1198919).
  • CVE-2022-24883: Fixed authentication against invalid SAM files (bsc#1198921).

Список пакетов

SUSE Linux Enterprise Module for Package Hub 15 SP4
freerdp-2.4.0-150400.3.3.1
freerdp-devel-2.4.0-150400.3.3.1
freerdp-proxy-2.4.0-150400.3.3.1
libfreerdp2-2.4.0-150400.3.3.1
libwinpr2-2.4.0-150400.3.3.1
winpr2-devel-2.4.0-150400.3.3.1
SUSE Linux Enterprise Workstation Extension 15 SP4
freerdp-2.4.0-150400.3.3.1
freerdp-devel-2.4.0-150400.3.3.1
freerdp-proxy-2.4.0-150400.3.3.1
libfreerdp2-2.4.0-150400.3.3.1
libwinpr2-2.4.0-150400.3.3.1
winpr2-devel-2.4.0-150400.3.3.1
openSUSE Leap 15.4
freerdp-2.4.0-150400.3.3.1
freerdp-devel-2.4.0-150400.3.3.1
freerdp-proxy-2.4.0-150400.3.3.1
freerdp-server-2.4.0-150400.3.3.1
freerdp-wayland-2.4.0-150400.3.3.1
libfreerdp2-2.4.0-150400.3.3.1
libuwac0-0-2.4.0-150400.3.3.1
libwinpr2-2.4.0-150400.3.3.1
uwac0-0-devel-2.4.0-150400.3.3.1
winpr2-devel-2.4.0-150400.3.3.1

Описание

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP). In versions prior to 2.7.0, NT LAN Manager (NTLM) authentication does not properly abort when someone provides and empty password value. This issue affects FreeRDP based RDP Server implementations. RDP clients are not affected. The vulnerability is patched in FreeRDP 2.7.0. There are currently no known workarounds.


Затронутые продукты
SUSE Linux Enterprise Module for Package Hub 15 SP4:freerdp-2.4.0-150400.3.3.1
SUSE Linux Enterprise Module for Package Hub 15 SP4:freerdp-devel-2.4.0-150400.3.3.1
SUSE Linux Enterprise Module for Package Hub 15 SP4:freerdp-proxy-2.4.0-150400.3.3.1
SUSE Linux Enterprise Module for Package Hub 15 SP4:libfreerdp2-2.4.0-150400.3.3.1

Ссылки

Описание

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP). Prior to version 2.7.0, server side authentication against a `SAM` file might be successful for invalid credentials if the server has configured an invalid `SAM` file path. FreeRDP based clients are not affected. RDP server implementations using FreeRDP to authenticate against a `SAM` file are affected. Version 2.7.0 contains a fix for this issue. As a workaround, use custom authentication via `HashCallback` and/or ensure the `SAM` database path configured is valid and the application has file handles left.


Затронутые продукты
SUSE Linux Enterprise Module for Package Hub 15 SP4:freerdp-2.4.0-150400.3.3.1
SUSE Linux Enterprise Module for Package Hub 15 SP4:freerdp-devel-2.4.0-150400.3.3.1
SUSE Linux Enterprise Module for Package Hub 15 SP4:freerdp-proxy-2.4.0-150400.3.3.1
SUSE Linux Enterprise Module for Package Hub 15 SP4:libfreerdp2-2.4.0-150400.3.3.1

Ссылки