Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2021-41159

Опубликовано: 21 окт. 2021
Источник: ubuntu
Приоритет: medium
CVSS2: 6.8
CVSS3: 5.8

Описание

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. All FreeRDP clients prior to version 2.4.1 using gateway connections (/gt:rpc) fail to validate input data. A malicious gateway might allow client memory to be written out of bounds. This issue has been resolved in version 2.4.1. If you are unable to update then use /gt:http rather than /gt:rdp connections if possible or use a direct connection without a gateway.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
esm-apps/bionic

needs-triage

esm-infra/xenial

needs-triage

trusty

ignored

end of standard support
upstream

needs-triage

xenial

ignored

end of standard support

Показывать по

РелизСтатусПримечание
bionic

released

2.2.0+dfsg1-0ubuntu0.18.04.2
devel

released

2.3.0+dfsg1-2ubuntu2
esm-apps/noble

released

2.3.0+dfsg1-2ubuntu2
esm-infra/bionic

not-affected

2.2.0+dfsg1-0ubuntu0.18.04.2
esm-infra/focal

not-affected

2.2.0+dfsg1-0ubuntu0.20.04.2
focal

released

2.2.0+dfsg1-0ubuntu0.20.04.2
hirsute

released

2.3.0+dfsg1-1ubuntu0.1
impish

released

2.3.0+dfsg1-2ubuntu0.1
jammy

released

2.3.0+dfsg1-2ubuntu2
kinetic

released

2.3.0+dfsg1-2ubuntu2

Показывать по

6.8 Medium

CVSS2

5.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 8.8
redhat
почти 4 года назад

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. All FreeRDP clients prior to version 2.4.1 using gateway connections (`/gt:rpc`) fail to validate input data. A malicious gateway might allow client memory to be written out of bounds. This issue has been resolved in version 2.4.1. If you are unable to update then use `/gt:http` rather than /gt:rdp connections if possible or use a direct connection without a gateway.

CVSS3: 5.8
nvd
почти 4 года назад

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. All FreeRDP clients prior to version 2.4.1 using gateway connections (`/gt:rpc`) fail to validate input data. A malicious gateway might allow client memory to be written out of bounds. This issue has been resolved in version 2.4.1. If you are unable to update then use `/gt:http` rather than /gt:rdp connections if possible or use a direct connection without a gateway.

CVSS3: 5.8
debian
почти 4 года назад

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), ...

CVSS3: 8.8
fstec
почти 4 года назад

Уязвимость реализации протокола удалённого рабочего стола FreeRDP, связанная с записью за границами буфера, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

suse-cvrf
почти 3 года назад

Security update for freerdp

6.8 Medium

CVSS2

5.8 Medium

CVSS3