Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-4478

Опубликовано: 16 мая 2025
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 7.1

Описание

A flaw was found in the FreeRDP used by Anaconda's remote install feature, where a crafted RDP packet could trigger a segmentation fault. This issue causes the service to crash and remain defunct, resulting in a denial of service. It occurs pre-boot and is likely due to a NULL pointer dereference. Rebooting is required to recover the system.

РелизСтатусПримечание
devel

DNE

esm-apps/bionic

not-affected

3.x only
esm-infra/xenial

not-affected

3.x only
jammy

DNE

noble

DNE

oracular

DNE

plucky

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

not-affected

3.x only
esm-apps/noble

not-affected

3.x only
esm-infra/bionic

not-affected

3.x only
esm-infra/focal

not-affected

3.x only
jammy

not-affected

3.x only
noble

not-affected

3.x only
oracular

not-affected

3.x only
plucky

not-affected

3.x only
upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

not-affected

3.15.0+dfsg-2.1
jammy

DNE

noble

released

3.5.1+dfsg1-0ubuntu1.1
oracular

ignored

end of life
plucky

released

3.14.0+dfsg-1ubuntu1.1
upstream

released

3.15.0+dfsg-2.1

Показывать по

EPSS

Процентиль: 13%
0.00045
Низкий

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.1
redhat
3 месяца назад

A flaw was found in the FreeRDP used by Anaconda's remote install feature, where a crafted RDP packet could trigger a segmentation fault. This issue causes the service to crash and remain defunct, resulting in a denial of service. It occurs pre-boot and is likely due to a NULL pointer dereference. Rebooting is required to recover the system.

CVSS3: 7.1
nvd
3 месяца назад

A flaw was found in the FreeRDP used by Anaconda's remote install feature, where a crafted RDP packet could trigger a segmentation fault. This issue causes the service to crash and remain defunct, resulting in a denial of service. It occurs pre-boot and is likely due to a NULL pointer dereference. Rebooting is required to recover the system.

CVSS3: 7.1
debian
3 месяца назад

A flaw was found in the FreeRDP used by Anaconda's remote install feat ...

CVSS3: 7.1
github
3 месяца назад

A flaw was found in the gnome-remote-desktop used by Anaconda's remote install feature, where a crafted RDP packet could trigger a segmentation fault. This issue causes the service to crash and remain defunct, resulting in a denial of service. It occurs pre-boot and is likely due to a NULL pointer dereference. Rebooting is required to recover the system.

oracle-oval
около 1 месяца назад

ELSA-2025-9307: freerdp security update (MODERATE)

EPSS

Процентиль: 13%
0.00045
Низкий

7.1 High

CVSS3