OOB Read in RLEDECOMPRESS in FreeRDP
8Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 3.1epss 1.8%
probabilidad de explotación
1.8%top 22% de las CVE
explotación observada
noninguna fuente lo reporta
In FreeRDP before version 2.1.2, there is an out of bounds read in RLEDECOMPRESS. All FreeRDP based clients with sessions with color depth < 32 are affected. This is fixed in version 2.1.2.
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Productos afectados
FreeRDP · FreeRDPReferencias
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00080.htmlhttps://github.com/FreeRDP/FreeRDP/commit/0a98c450c58ec150e44781c89aa6f8e7e0f571f5https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-7rhj-856w-82p8https://lists.debian.org/debian-lts-announce/2023/10/msg00008.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6Y35HBHG2INICLSGCIKNAR7GCXEHQACQ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XOZLH35OJWIQLM7FYDXAP2EAUBDXE76V/https://usn.ubuntu.com/4481-1/http://www.freerdp.com/2020/06/22/2_1_2-released