Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2023-39355

Опубликовано: 31 авг. 2023
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 7

Описание

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Versions of FreeRDP on the 3.x release branch before beta3 are subject to a Use-After-Free in processing RDPGFX_CMDID_RESETGRAPHICS packets. If context->maxPlaneSize is 0, context->planesBuffer will be freed. However, without updating context->planesBuffer, this leads to a Use-After-Free exploit vector. In most environments this should only result in a crash. This issue has been addressed in version 3.0.0-beta3 and users of the beta 3.x releases are advised to upgrade. There are no known workarounds for this vulnerability.

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

not-affected

2.10.0+dfsg1-1.1
esm-infra/bionic

not-affected

2.2.0+dfsg1-0ubuntu0.18.04.4
esm-infra/focal

not-affected

2.2.0+dfsg1-0ubuntu0.20.04.4
focal

not-affected

2.2.0+dfsg1-0ubuntu0.20.04.4
jammy

not-affected

2.6.1+dfsg1-3ubuntu2.3
lunar

not-affected

2.10.0+dfsg1-1
mantic

not-affected

2.10.0+dfsg1-1.1
trusty

ignored

end of standard support
upstream

needs-triage

Показывать по

EPSS

Процентиль: 51%
0.00277
Низкий

7 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
больше 2 лет назад

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Versions of FreeRDP on the 3.x release branch before beta3 are subject to a Use-After-Free in processing `RDPGFX_CMDID_RESETGRAPHICS` packets. If `context->maxPlaneSize` is 0, `context->planesBuffer` will be freed. However, without updating `context->planesBuffer`, this leads to a Use-After-Free exploit vector. In most environments this should only result in a crash. This issue has been addressed in version 3.0.0-beta3 and users of the beta 3.x releases are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 7
nvd
больше 2 лет назад

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Versions of FreeRDP on the 3.x release branch before beta3 are subject to a Use-After-Free in processing `RDPGFX_CMDID_RESETGRAPHICS` packets. If `context->maxPlaneSize` is 0, `context->planesBuffer` will be freed. However, without updating `context->planesBuffer`, this leads to a Use-After-Free exploit vector. In most environments this should only result in a crash. This issue has been addressed in version 3.0.0-beta3 and users of the beta 3.x releases are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 7
debian
больше 2 лет назад

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), ...

CVSS3: 7
fstec
больше 2 лет назад

Уязвимость функции RDPGFX_CMDID_RESETGRAPHICS() RDP-клиента FreeRDP, позволяющая нарушителю вызвать отказ в обслуживании или оказать иное воздействие

EPSS

Процентиль: 51%
0.00277
Низкий

7 High

CVSS3