Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-67289

Опубликовано: 01 авг. 2026
Источник: ubuntu
Приоритет: medium
CVSS3: 9.8

Описание

FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client's ServerHostname and, when the client connects through an HTTP proxy, is written directly into the proxy CONNECT request line and Host header by http_proxy_connect() without filtering. A malicious or compromised RDP server can send a crafted redirection PDU containing embedded control characters to inject arbitrary headers/requests into the HTTP proxy CONNECT request.

РелизСтатусПримечание
devel

DNE

esm-apps/bionic

needs-triage

esm-infra-legacy/xenial

needs-triage

jammy

DNE

noble

DNE

resolute

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps/noble

needs-triage

esm-infra/bionic

needs-triage

esm-infra/focal

needs-triage

jammy

needs-triage

noble

needs-triage

resolute

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

not-affected

3.30.0+dfsg-1ubuntu1
jammy

DNE

noble

released

3.30.0+dfsg-0ubuntu0.24.04.1
resolute

released

3.30.0+dfsg-0ubuntu0.26.04.1
upstream

needs-triage

Показывать по

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 5
redhat
около 1 месяца назад

FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client's ServerHostname and, when the client connects through an HTTP proxy, is written directly into the proxy CONNECT request line and Host header by http_proxy_connect() without filtering. A malicious or compromised RDP server can send a crafted redirection PDU containing embedded control characters to inject arbitrary headers/requests into the HTTP proxy CONNECT request.

CVSS3: 9.8
nvd
около 1 месяца назад

FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client's ServerHostname and, when the client connects through an HTTP proxy, is written directly into the proxy CONNECT request line and Host header by http_proxy_connect() without filtering. A malicious or compromised RDP server can send a crafted redirection PDU containing embedded control characters to inject arbitrary headers/requests into the HTTP proxy CONNECT request.

CVSS3: 9.8
debian
около 1 месяца назад

FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate ...

CVSS3: 9.8
github
около 1 месяца назад

FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client's ServerHostname and, when the client connects through an HTTP proxy, is written directly into the proxy CONNECT request line and Host header by http_proxy_connect() without filtering. A malicious or compromised RDP server can send a crafted redirection PDU containing embedded control characters to inject arbitrary headers/requests into the HTTP proxy CONNECT request.

CVSS3: 9.8
fstec
около 2 месяцев назад

Уязвимость функции http_proxy_connect() RDP-клиента FreeRDP, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

9.8 Critical

CVSS3