PT-2026-67282 · Freerdp · Freerdp
CVE-2026-67302
·
Published
2026-08-01
·
Updated
2026-08-01
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
FreeRDP versions prior to 3.29.0
Description
The rdpecam camera redirection client contains a divide-by-zero issue. The function
ecam dev process start streams request() parses a server-controlled CAM MEDIA TYPE DESCRIPTION from a StartStreamsRequest PDU but fails to validate the FrameRateDenominator variable. If a compromised RDP server sends a StartStreamsRequest where FrameRateDenominator is set to zero, the function ecam encoder context init() attempts to divide FrameRateNumerator by FrameRateDenominator, resulting in a SIGFPE (signal floating-point exception) and the termination of the client process. This issue is only reachable if camera redirection is enabled on the client.Recommendations
Update to version 3.29.0.
Disable camera redirection on the client to prevent the channel from being reachable.
Exploit
Fix
Divide By Zero
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Freerdp