Логотип exploitDog
bind: "CVE-2022-39347"
Консоль
Логотип exploitDog

exploitDog

bind: "CVE-2022-39347"

Количество 10

Количество 10

ubuntu логотип

CVE-2022-39347

больше 2 лет назад

FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing path canonicalization and base path check for `drive` channel. A malicious server can trick a FreeRDP based client to read files outside the shared directory. This issue has been addressed in version 2.9.0 and all users are advised to upgrade. Users unable to upgrade should not use the `/drive`, `/drives` or `+home-drive` redirection switch.

CVSS3: 2.6
EPSS: Низкий
redhat логотип

CVE-2022-39347

больше 2 лет назад

FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing path canonicalization and base path check for `drive` channel. A malicious server can trick a FreeRDP based client to read files outside the shared directory. This issue has been addressed in version 2.9.0 and all users are advised to upgrade. Users unable to upgrade should not use the `/drive`, `/drives` or `+home-drive` redirection switch.

CVSS3: 4.8
EPSS: Низкий
nvd логотип

CVE-2022-39347

больше 2 лет назад

FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing path canonicalization and base path check for `drive` channel. A malicious server can trick a FreeRDP based client to read files outside the shared directory. This issue has been addressed in version 2.9.0 and all users are advised to upgrade. Users unable to upgrade should not use the `/drive`, `/drives` or `+home-drive` redirection switch.

CVSS3: 2.6
EPSS: Низкий
debian логотип

CVE-2022-39347

больше 2 лет назад

FreeRDP is a free remote desktop protocol library and clients. Affecte ...

CVSS3: 2.6
EPSS: Низкий
fstec логотип

BDU:2022-06975

больше 2 лет назад

Уязвимость канала перенаправления диска реализации протокола удалённого рабочего стола FreeRDP, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:0400-1

больше 2 лет назад

Security update for freerdp

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:0399-1

больше 2 лет назад

Security update for freerdp

EPSS: Низкий
redos логотип

ROS-20221121-02

больше 2 лет назад

Множественные уязвимости FreeRDP

CVSS3: 9.1
EPSS: Низкий
oracle-oval логотип

ELSA-2023-2851

около 2 лет назад

ELSA-2023-2851: freerdp security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2023-2326

около 2 лет назад

ELSA-2023-2326: freerdp security update (MODERATE)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2022-39347

FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing path canonicalization and base path check for `drive` channel. A malicious server can trick a FreeRDP based client to read files outside the shared directory. This issue has been addressed in version 2.9.0 and all users are advised to upgrade. Users unable to upgrade should not use the `/drive`, `/drives` or `+home-drive` redirection switch.

CVSS3: 2.6
0%
Низкий
больше 2 лет назад
redhat логотип
CVE-2022-39347

FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing path canonicalization and base path check for `drive` channel. A malicious server can trick a FreeRDP based client to read files outside the shared directory. This issue has been addressed in version 2.9.0 and all users are advised to upgrade. Users unable to upgrade should not use the `/drive`, `/drives` or `+home-drive` redirection switch.

CVSS3: 4.8
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2022-39347

FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing path canonicalization and base path check for `drive` channel. A malicious server can trick a FreeRDP based client to read files outside the shared directory. This issue has been addressed in version 2.9.0 and all users are advised to upgrade. Users unable to upgrade should not use the `/drive`, `/drives` or `+home-drive` redirection switch.

CVSS3: 2.6
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2022-39347

FreeRDP is a free remote desktop protocol library and clients. Affecte ...

CVSS3: 2.6
0%
Низкий
больше 2 лет назад
fstec логотип
BDU:2022-06975

Уязвимость канала перенаправления диска реализации протокола удалённого рабочего стола FreeRDP, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:0400-1

Security update for freerdp

больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:0399-1

Security update for freerdp

больше 2 лет назад
redos логотип
ROS-20221121-02

Множественные уязвимости FreeRDP

CVSS3: 9.1
больше 2 лет назад
oracle-oval логотип
ELSA-2023-2851

ELSA-2023-2851: freerdp security update (MODERATE)

около 2 лет назад
oracle-oval логотип
ELSA-2023-2326

ELSA-2023-2326: freerdp security update (MODERATE)

около 2 лет назад

Уязвимостей на страницу