Improper Restriction of Operations within the Bounds of a Memory Buffer in FreeRDP
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.5epss 1.3%
exploitation probability
1.3%top 30% of all CVEs
observed exploitation
nono source reports it
In FreeRDP after 1.0 and before 2.0.0, there is a stream out-of-bounds seek in update_read_synchronize that could lead to a later out-of-bounds read.
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:L
Affected products
FreeRDP · FreeRDPReferences
https://github.com/FreeRDP/FreeRDP/commit/ed53cd148f43cbab905eaa0f5308c2bf3c48cc37https://github.com/FreeRDP/FreeRDP/issues/6006https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-hx48-wmmm-mr5qhttps://lists.debian.org/debian-lts-announce/2020/08/msg00054.htmlhttps://lists.debian.org/debian-lts-announce/2023/10/msg00008.htmlhttps://usn.ubuntu.com/4379-1/https://usn.ubuntu.com/4382-1/