Количество 13
Количество 13
BDU:2026-11998
Уязвимость функции rpc_client_recv_fragment() файла libfreerdp/core/gateway/rpc_client.c RDP-клиента FreeRDP, позволяющая нарушителю вызвать отказ в обслуживании и выполнить произвольный код
ROS-20260824-80-0009
Уязвимость freerdp3
ROS-20260824-73-0010
Уязвимость freerdp3
CVE-2026-55194
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, rpc_client_recv_fragment in libfreerdp/core/gateway/rpc_client.c ensures the response reassembly stream capacity using only the server-declared alloc_hint rather than the actual StubLength about to be written. A malicious TS Gateway can send a PTYPE_RESPONSE with a small alloc_hint and a much larger frag_length, causing Stream_Write to copy attacker-controlled stub data beyond the 4096-byte pdu->s buffer. This can crash the client and may permit code execution through heap corruption. This issue is fixed in version 3.27.0.
CVE-2026-55194
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, rpc_client_recv_fragment in libfreerdp/core/gateway/rpc_client.c ensures the response reassembly stream capacity using only the server-declared alloc_hint rather than the actual StubLength about to be written. A malicious TS Gateway can send a PTYPE_RESPONSE with a small alloc_hint and a much larger frag_length, causing Stream_Write to copy attacker-controlled stub data beyond the 4096-byte pdu->s buffer. This can crash the client and may permit code execution through heap corruption. This issue is fixed in version 3.27.0.
CVE-2026-55194
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, rpc_client_recv_fragment in libfreerdp/core/gateway/rpc_client.c ensures the response reassembly stream capacity using only the server-declared alloc_hint rather than the actual StubLength about to be written. A malicious TS Gateway can send a PTYPE_RESPONSE with a small alloc_hint and a much larger frag_length, causing Stream_Write to copy attacker-controlled stub data beyond the 4096-byte pdu->s buffer. This can crash the client and may permit code execution through heap corruption. This issue is fixed in version 3.27.0.
CVE-2026-55194
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...
RLSA-2026:62571
Important: freerdp security update
RLSA-2026:61379
Important: freerdp security update
ELSA-2026-62571-0
ELSA-2026-62571-0: freerdp security update (IMPORTANT)
ELSA-2026-61379-0
ELSA-2026-61379-0: freerdp security update (IMPORTANT)
RLSA-2026:61378
Important: freerdp security update
ELSA-2026-61378-0
ELSA-2026-61378-0: freerdp security update (IMPORTANT)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2026-11998 Уязвимость функции rpc_client_recv_fragment() файла libfreerdp/core/gateway/rpc_client.c RDP-клиента FreeRDP, позволяющая нарушителю вызвать отказ в обслуживании и выполнить произвольный код | CVSS3: 8.8 | 0% Низкий | 3 месяца назад | |
ROS-20260824-80-0009 Уязвимость freerdp3 | CVSS3: 8.8 | 0% Низкий | 30 дней назад | |
ROS-20260824-73-0010 Уязвимость freerdp3 | CVSS3: 8.8 | 0% Низкий | 30 дней назад | |
CVE-2026-55194 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, rpc_client_recv_fragment in libfreerdp/core/gateway/rpc_client.c ensures the response reassembly stream capacity using only the server-declared alloc_hint rather than the actual StubLength about to be written. A malicious TS Gateway can send a PTYPE_RESPONSE with a small alloc_hint and a much larger frag_length, causing Stream_Write to copy attacker-controlled stub data beyond the 4096-byte pdu->s buffer. This can crash the client and may permit code execution through heap corruption. This issue is fixed in version 3.27.0. | 0% Низкий | около 1 месяца назад | ||
CVE-2026-55194 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, rpc_client_recv_fragment in libfreerdp/core/gateway/rpc_client.c ensures the response reassembly stream capacity using only the server-declared alloc_hint rather than the actual StubLength about to be written. A malicious TS Gateway can send a PTYPE_RESPONSE with a small alloc_hint and a much larger frag_length, causing Stream_Write to copy attacker-controlled stub data beyond the 4096-byte pdu->s buffer. This can crash the client and may permit code execution through heap corruption. This issue is fixed in version 3.27.0. | CVSS3: 8.8 | 0% Низкий | около 1 месяца назад | |
CVE-2026-55194 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, rpc_client_recv_fragment in libfreerdp/core/gateway/rpc_client.c ensures the response reassembly stream capacity using only the server-declared alloc_hint rather than the actual StubLength about to be written. A malicious TS Gateway can send a PTYPE_RESPONSE with a small alloc_hint and a much larger frag_length, causing Stream_Write to copy attacker-controlled stub data beyond the 4096-byte pdu->s buffer. This can crash the client and may permit code execution through heap corruption. This issue is fixed in version 3.27.0. | 0% Низкий | около 1 месяца назад | ||
CVE-2026-55194 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ... | 0% Низкий | около 1 месяца назад | ||
RLSA-2026:62571 Important: freerdp security update | 20 дней назад | |||
RLSA-2026:61379 Important: freerdp security update | 22 дня назад | |||
ELSA-2026-62571-0 ELSA-2026-62571-0: freerdp security update (IMPORTANT) | 21 день назад | |||
ELSA-2026-61379-0 ELSA-2026-61379-0: freerdp security update (IMPORTANT) | 22 дня назад | |||
RLSA-2026:61378 Important: freerdp security update | 21 день назад | |||
ELSA-2026-61378-0 ELSA-2026-61378-0: freerdp security update (IMPORTANT) | 22 дня назад |
Уязвимостей на страницу