Описание
FreeRDP is a free remote desktop protocol library and clients. In affected versions there is an out of bound read in ZGFX decoder component of FreeRDP. A malicious server can trick a FreeRDP based client to read out of bound data and try to decode it likely resulting in a crash. This issue has been addressed in the 2.9.0 release. Users are advised to upgrade.
Релиз | Статус | Примечание |
---|---|---|
bionic | not-affected | |
esm-apps/bionic | not-affected | |
esm-infra/focal | DNE | |
esm-infra/xenial | not-affected | |
focal | DNE | |
jammy | DNE | |
kinetic | DNE | |
trusty | ignored | end of standard support |
upstream | not-affected | |
xenial | ignored | end of standard support |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
bionic | released | 2.2.0+dfsg1-0ubuntu0.18.04.4 |
devel | released | 2.8.1+dfsg1-1ubuntu1 |
esm-infra/bionic | not-affected | 2.2.0+dfsg1-0ubuntu0.18.04.4 |
esm-infra/focal | not-affected | 2.2.0+dfsg1-0ubuntu0.20.04.4 |
focal | released | 2.2.0+dfsg1-0ubuntu0.20.04.4 |
jammy | released | 2.6.1+dfsg1-3ubuntu2.3 |
kinetic | released | 2.8.1+dfsg1-0ubuntu1.1 |
trusty | ignored | end of standard support |
upstream | needs-triage | |
xenial | ignored | end of standard support |
Показывать по
EPSS
4.8 Medium
CVSS3
Связанные уязвимости
FreeRDP is a free remote desktop protocol library and clients. In affected versions there is an out of bound read in ZGFX decoder component of FreeRDP. A malicious server can trick a FreeRDP based client to read out of bound data and try to decode it likely resulting in a crash. This issue has been addressed in the 2.9.0 release. Users are advised to upgrade.
FreeRDP is a free remote desktop protocol library and clients. In affected versions there is an out of bound read in ZGFX decoder component of FreeRDP. A malicious server can trick a FreeRDP based client to read out of bound data and try to decode it likely resulting in a crash. This issue has been addressed in the 2.9.0 release. Users are advised to upgrade.
FreeRDP is a free remote desktop protocol library and clients. In affe ...
Уязвимость функции zgfx_decompress_segment() декодера ZGFX реализации протокола удалённого рабочего стола FreeRDP, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
4.8 Medium
CVSS3