Количество 12
Количество 12
CVE-2026-67289
FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client's ServerHostname and, when the client connects through an HTTP proxy, is written directly into the proxy CONNECT request line and Host header by http_proxy_connect() without filtering. A malicious or compromised RDP server can send a crafted redirection PDU containing embedded control characters to inject arbitrary headers/requests into the HTTP proxy CONNECT request.
CVE-2026-67289
FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client's ServerHostname and, when the client connects through an HTTP proxy, is written directly into the proxy CONNECT request line and Host header by http_proxy_connect() without filtering. A malicious or compromised RDP server can send a crafted redirection PDU containing embedded control characters to inject arbitrary headers/requests into the HTTP proxy CONNECT request.
CVE-2026-67289
FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client's ServerHostname and, when the client connects through an HTTP proxy, is written directly into the proxy CONNECT request line and Host header by http_proxy_connect() without filtering. A malicious or compromised RDP server can send a crafted redirection PDU containing embedded control characters to inject arbitrary headers/requests into the HTTP proxy CONNECT request.
CVE-2026-67289
FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate ...
GHSA-3x8f-6ffv-v2wc
FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client's ServerHostname and, when the client connects through an HTTP proxy, is written directly into the proxy CONNECT request line and Host header by http_proxy_connect() without filtering. A malicious or compromised RDP server can send a crafted redirection PDU containing embedded control characters to inject arbitrary headers/requests into the HTTP proxy CONNECT request.
BDU:2026-10983
Уязвимость функции http_proxy_connect() RDP-клиента FreeRDP, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации
RLSA-2026:54487
Important: freerdp security update
RLSA-2026:54485
Important: freerdp security update
ELSA-2026-54487
ELSA-2026-54487: freerdp security update (IMPORTANT)
ELSA-2026-54485
ELSA-2026-54485: freerdp security update (IMPORTANT)
RLSA-2026:54486
Important: freerdp security update
ELSA-2026-54486
ELSA-2026-54486: freerdp security update (IMPORTANT)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-67289 FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client's ServerHostname and, when the client connects through an HTTP proxy, is written directly into the proxy CONNECT request line and Host header by http_proxy_connect() without filtering. A malicious or compromised RDP server can send a crafted redirection PDU containing embedded control characters to inject arbitrary headers/requests into the HTTP proxy CONNECT request. | CVSS3: 9.8 | 0% Низкий | около 1 месяца назад | |
CVE-2026-67289 FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client's ServerHostname and, when the client connects through an HTTP proxy, is written directly into the proxy CONNECT request line and Host header by http_proxy_connect() without filtering. A malicious or compromised RDP server can send a crafted redirection PDU containing embedded control characters to inject arbitrary headers/requests into the HTTP proxy CONNECT request. | CVSS3: 5 | 0% Низкий | около 1 месяца назад | |
CVE-2026-67289 FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client's ServerHostname and, when the client connects through an HTTP proxy, is written directly into the proxy CONNECT request line and Host header by http_proxy_connect() without filtering. A malicious or compromised RDP server can send a crafted redirection PDU containing embedded control characters to inject arbitrary headers/requests into the HTTP proxy CONNECT request. | CVSS3: 9.8 | 0% Низкий | около 1 месяца назад | |
CVE-2026-67289 FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate ... | CVSS3: 9.8 | 0% Низкий | около 1 месяца назад | |
GHSA-3x8f-6ffv-v2wc FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client's ServerHostname and, when the client connects through an HTTP proxy, is written directly into the proxy CONNECT request line and Host header by http_proxy_connect() without filtering. A malicious or compromised RDP server can send a crafted redirection PDU containing embedded control characters to inject arbitrary headers/requests into the HTTP proxy CONNECT request. | CVSS3: 9.8 | 0% Низкий | около 1 месяца назад | |
BDU:2026-10983 Уязвимость функции http_proxy_connect() RDP-клиента FreeRDP, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации | CVSS3: 9.8 | 0% Низкий | около 2 месяцев назад | |
RLSA-2026:54487 Important: freerdp security update | 18 дней назад | |||
RLSA-2026:54485 Important: freerdp security update | 19 дней назад | |||
ELSA-2026-54487 ELSA-2026-54487: freerdp security update (IMPORTANT) | 20 дней назад | |||
ELSA-2026-54485 ELSA-2026-54485: freerdp security update (IMPORTANT) | 20 дней назад | |||
RLSA-2026:54486 Important: freerdp security update | 19 дней назад | |||
ELSA-2026-54486 ELSA-2026-54486: freerdp security update (IMPORTANT) | 20 дней назад |
Уязвимостей на страницу