PT-2026-25333 · Freerdp+2 · Freerdp+2
CVSS v3.1
8.2
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
FreeRDP versions prior to 3.24.0
Description
FreeRDP is a free implementation of the Remote Desktop Protocol. A client-side heap out-of-bounds read/write issue exists in FreeRDP's bitmap cache subsystem. This is due to an incorrect boundary check in the
bitmap cache put function when handling a CACHE BITMAP ORDER (Rev1) message with a cacheId equal to maxCells. This allows a malicious server to bypass security checks and access memory outside the allocated array.Recommendations
Update to version 3.24.0 or later.
Exploit
Correção
DoS
Heap Based Buffer Overflow
Memory Corruption
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Freerdp
Red Os
Rocky Linux