Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 6

Количество 6

ubuntu логотип

CVE-2025-68118

8 месяцев назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.20.0, a vulnerability exists in FreeRDP’s certificate handling code on Windows platforms. The function `freerdp_certificate_data_hash_ uses` the Microsoft-specific `_snprintf` function to format certificate cache filenames without guaranteeing NUL termination when truncation occurs. According to Microsoft documentation, `_snprintf` does not append a terminating NUL byte if the formatted output exceeds the destination buffer size. If an attacker controls the hostname value (for example via server redirection or a crafted .rdp file), the resulting filename buffer may not be NUL-terminated. Subsequent string operations performed on this buffer may read beyond the allocated memory region, resulting in a heap-based out-of-bounds read. In default configurations, the connection is typically terminated before sensitive data can be meaningfully exposed, but unintended memory read or a client crash may still...

CVSS3: 9.1
EPSS: Низкий
nvd логотип

CVE-2025-68118

8 месяцев назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.20.0, a vulnerability exists in FreeRDP’s certificate handling code on Windows platforms. The function `freerdp_certificate_data_hash_ uses` the Microsoft-specific `_snprintf` function to format certificate cache filenames without guaranteeing NUL termination when truncation occurs. According to Microsoft documentation, `_snprintf` does not append a terminating NUL byte if the formatted output exceeds the destination buffer size. If an attacker controls the hostname value (for example via server redirection or a crafted .rdp file), the resulting filename buffer may not be NUL-terminated. Subsequent string operations performed on this buffer may read beyond the allocated memory region, resulting in a heap-based out-of-bounds read. In default configurations, the connection is typically terminated before sensitive data can be meaningfully exposed, but unintended memory read or a client crash may still oc

CVSS3: 9.1
EPSS: Низкий
debian логотип

CVE-2025-68118

8 месяцев назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...

CVSS3: 9.1
EPSS: Низкий
fstec логотип

BDU:2026-10005

8 месяцев назад

Уязвимость функции freerdp_certificate_data_hash_() RDP-клиента FreeRDP, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 9.1
EPSS: Низкий
redos логотип

ROS-20260610-73-0034

около 2 месяцев назад

Уязвимость freerdp3

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20260610-73-0033

около 2 месяцев назад

Уязвимость freerdp

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-68118

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.20.0, a vulnerability exists in FreeRDP’s certificate handling code on Windows platforms. The function `freerdp_certificate_data_hash_ uses` the Microsoft-specific `_snprintf` function to format certificate cache filenames without guaranteeing NUL termination when truncation occurs. According to Microsoft documentation, `_snprintf` does not append a terminating NUL byte if the formatted output exceeds the destination buffer size. If an attacker controls the hostname value (for example via server redirection or a crafted .rdp file), the resulting filename buffer may not be NUL-terminated. Subsequent string operations performed on this buffer may read beyond the allocated memory region, resulting in a heap-based out-of-bounds read. In default configurations, the connection is typically terminated before sensitive data can be meaningfully exposed, but unintended memory read or a client crash may still...

CVSS3: 9.1
0%
Низкий
8 месяцев назад
nvd логотип
CVE-2025-68118

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.20.0, a vulnerability exists in FreeRDP’s certificate handling code on Windows platforms. The function `freerdp_certificate_data_hash_ uses` the Microsoft-specific `_snprintf` function to format certificate cache filenames without guaranteeing NUL termination when truncation occurs. According to Microsoft documentation, `_snprintf` does not append a terminating NUL byte if the formatted output exceeds the destination buffer size. If an attacker controls the hostname value (for example via server redirection or a crafted .rdp file), the resulting filename buffer may not be NUL-terminated. Subsequent string operations performed on this buffer may read beyond the allocated memory region, resulting in a heap-based out-of-bounds read. In default configurations, the connection is typically terminated before sensitive data can be meaningfully exposed, but unintended memory read or a client crash may still oc

CVSS3: 9.1
0%
Низкий
8 месяцев назад
debian логотип
CVE-2025-68118

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...

CVSS3: 9.1
0%
Низкий
8 месяцев назад
fstec логотип
BDU:2026-10005

Уязвимость функции freerdp_certificate_data_hash_() RDP-клиента FreeRDP, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 9.1
0%
Низкий
8 месяцев назад
redos логотип
ROS-20260610-73-0034

Уязвимость freerdp3

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
redos логотип
ROS-20260610-73-0033

Уязвимость freerdp

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу