Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2024:1610-1

Опубликовано: 10 мая 2024
Источник: suse-cvrf

Описание

Security update for freerdp

This update for freerdp fixes the following issues:

  • CVE-2024-32039: Fixed an out-of-bounds write with variables of type uint32 (bsc#1223293)
  • CVE-2024-32040: Fixed a integer underflow when using the 'NSC' codec (bsc#1223294)
  • CVE-2024-32041: Fixed an out-of-bounds read in Stream_GetRemainingLength() (bsc#1223295)
  • CVE-2024-32458: Fixed an out-of-bounds read on pSrcData[] (bsc#1223296)
  • CVE-2024-32459: Fixed an out-of-bounds read in case SrcSize less than 4 (bsc#1223297)
  • CVE-2024-32460: Fixed an out-of-bounds read when using '/bpp:32' legacy 'GDI' drawing path (bsc#1223298)

Список пакетов

SUSE Linux Enterprise Module for Package Hub 15 SP5
freerdp-2.4.0-150400.3.29.1
freerdp-devel-2.4.0-150400.3.29.1
freerdp-proxy-2.4.0-150400.3.29.1
freerdp-server-2.4.0-150400.3.29.1
freerdp-wayland-2.4.0-150400.3.29.1
libfreerdp2-2.4.0-150400.3.29.1
libuwac0-0-2.4.0-150400.3.29.1
libwinpr2-2.4.0-150400.3.29.1
uwac0-0-devel-2.4.0-150400.3.29.1
winpr2-devel-2.4.0-150400.3.29.1
SUSE Linux Enterprise Workstation Extension 15 SP5
freerdp-2.4.0-150400.3.29.1
freerdp-devel-2.4.0-150400.3.29.1
freerdp-proxy-2.4.0-150400.3.29.1
libfreerdp2-2.4.0-150400.3.29.1
libwinpr2-2.4.0-150400.3.29.1
winpr2-devel-2.4.0-150400.3.29.1
openSUSE Leap 15.5
freerdp-2.4.0-150400.3.29.1
freerdp-devel-2.4.0-150400.3.29.1
freerdp-proxy-2.4.0-150400.3.29.1
freerdp-server-2.4.0-150400.3.29.1
freerdp-wayland-2.4.0-150400.3.29.1
libfreerdp2-2.4.0-150400.3.29.1
libuwac0-0-2.4.0-150400.3.29.1
libwinpr2-2.4.0-150400.3.29.1
uwac0-0-devel-2.4.0-150400.3.29.1
winpr2-devel-2.4.0-150400.3.29.1

Описание

FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients using a version of FreeRDP prior to 3.5.0 or 2.11.6 are vulnerable to integer overflow and out-of-bounds write. Versions 3.5.0 and 2.11.6 patch the issue. As a workaround, do not use `/gfx` options (e.g. deactivate with `/bpp:32` or `/rfx` as it is on by default).


Затронутые продукты
SUSE Linux Enterprise Module for Package Hub 15 SP5:freerdp-2.4.0-150400.3.29.1
SUSE Linux Enterprise Module for Package Hub 15 SP5:freerdp-devel-2.4.0-150400.3.29.1
SUSE Linux Enterprise Module for Package Hub 15 SP5:freerdp-proxy-2.4.0-150400.3.29.1
SUSE Linux Enterprise Module for Package Hub 15 SP5:freerdp-server-2.4.0-150400.3.29.1

Ссылки

Описание

FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients that use a version of FreeRDP prior to 3.5.0 or 2.11.6 and have connections to servers using the `NSC` codec are vulnerable to integer underflow. Versions 3.5.0 and 2.11.6 patch the issue. As a workaround, do not use the NSC codec (e.g. use `-nsc`).


Затронутые продукты
SUSE Linux Enterprise Module for Package Hub 15 SP5:freerdp-2.4.0-150400.3.29.1
SUSE Linux Enterprise Module for Package Hub 15 SP5:freerdp-devel-2.4.0-150400.3.29.1
SUSE Linux Enterprise Module for Package Hub 15 SP5:freerdp-proxy-2.4.0-150400.3.29.1
SUSE Linux Enterprise Module for Package Hub 15 SP5:freerdp-server-2.4.0-150400.3.29.1

Ссылки

Описание

FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients that use a version of FreeRDP prior to 3.5.0 or 2.11.6 are vulnerable to out-of-bounds read. Versions 3.5.0 and 2.11.6 patch the issue. As a workaround, deactivate `/gfx` (on by default, set `/bpp` or `/rfx` options instead.


Затронутые продукты
SUSE Linux Enterprise Module for Package Hub 15 SP5:freerdp-2.4.0-150400.3.29.1
SUSE Linux Enterprise Module for Package Hub 15 SP5:freerdp-devel-2.4.0-150400.3.29.1
SUSE Linux Enterprise Module for Package Hub 15 SP5:freerdp-proxy-2.4.0-150400.3.29.1
SUSE Linux Enterprise Module for Package Hub 15 SP5:freerdp-server-2.4.0-150400.3.29.1

Ссылки

Описание

FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients that use a version of FreeRDP prior to 3.5.0 or 2.11.6 are vulnerable to out-of-bounds read. Versions 3.5.0 and 2.11.6 patch the issue. As a workaround, use `/gfx` or `/rfx` modes (on by default, require server side support).


Затронутые продукты
SUSE Linux Enterprise Module for Package Hub 15 SP5:freerdp-2.4.0-150400.3.29.1
SUSE Linux Enterprise Module for Package Hub 15 SP5:freerdp-devel-2.4.0-150400.3.29.1
SUSE Linux Enterprise Module for Package Hub 15 SP5:freerdp-proxy-2.4.0-150400.3.29.1
SUSE Linux Enterprise Module for Package Hub 15 SP5:freerdp-server-2.4.0-150400.3.29.1

Ссылки

Описание

FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients and servers that use a version of FreeRDP prior to 3.5.0 or 2.11.6 are vulnerable to out-of-bounds read. Versions 3.5.0 and 2.11.6 patch the issue. No known workarounds are available.


Затронутые продукты
SUSE Linux Enterprise Module for Package Hub 15 SP5:freerdp-2.4.0-150400.3.29.1
SUSE Linux Enterprise Module for Package Hub 15 SP5:freerdp-devel-2.4.0-150400.3.29.1
SUSE Linux Enterprise Module for Package Hub 15 SP5:freerdp-proxy-2.4.0-150400.3.29.1
SUSE Linux Enterprise Module for Package Hub 15 SP5:freerdp-server-2.4.0-150400.3.29.1

Ссылки

Описание

FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based based clients using `/bpp:32` legacy `GDI` drawing path with a version of FreeRDP prior to 3.5.0 or 2.11.6 are vulnerable to out-of-bounds read. Versions 3.5.0 and 2.11.6 patch the issue. As a workaround, use modern drawing paths (e.g. `/rfx` or `/gfx` options). The workaround requires server side support.


Затронутые продукты
SUSE Linux Enterprise Module for Package Hub 15 SP5:freerdp-2.4.0-150400.3.29.1
SUSE Linux Enterprise Module for Package Hub 15 SP5:freerdp-devel-2.4.0-150400.3.29.1
SUSE Linux Enterprise Module for Package Hub 15 SP5:freerdp-proxy-2.4.0-150400.3.29.1
SUSE Linux Enterprise Module for Package Hub 15 SP5:freerdp-server-2.4.0-150400.3.29.1

Ссылки
Уязвимость SUSE-SU-2024:1610-1