Количество 3
Количество 3
CVE-2026-67297
FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses in http_response_recv_body(). Attackers controlling a malicious RD Gateway endpoint can send oversized chunked response bodies to exhaust client memory resources without triggering the configured size limit.
CVE-2026-67297
FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when pr ...
GHSA-43rq-pv9m-43rf
FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses in http_response_recv_body(). Attackers controlling a malicious RD Gateway endpoint can send oversized chunked response bodies to exhaust client memory resources without triggering the configured size limit.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-67297 FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses in http_response_recv_body(). Attackers controlling a malicious RD Gateway endpoint can send oversized chunked response bodies to exhaust client memory resources without triggering the configured size limit. | CVSS3: 7.5 | 0% Низкий | 2 дня назад | |
CVE-2026-67297 FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when pr ... | CVSS3: 7.5 | 0% Низкий | 2 дня назад | |
GHSA-43rq-pv9m-43rf FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses in http_response_recv_body(). Attackers controlling a malicious RD Gateway endpoint can send oversized chunked response bodies to exhaust client memory resources without triggering the configured size limit. | CVSS3: 7.5 | 0% Низкий | 2 дня назад |
Уязвимостей на страницу