CVE-2023-39352
Summary
| CVE | CVE-2023-39352 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-08-31 21:15:00 UTC |
| Updated | 2023-10-18 14:49:00 UTC |
| Description | FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versions are subject to an invalid offset validation leading to Out Of Bound Write. This can be triggered when the values `rect->left` and `rect->top` are exactly equal to `surface->width` and `surface->height`. eg. `rect->left` == `surface->width` && `rect->top` == `surface->height`. In practice this should cause a crash. This issue has been addressed in versions 2.11.0 and 3.0.0-beta3. Users are advised to upgrade. There are no known workarounds for this vulnerability. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 38 Update: freerdp-2.11.1-1.fc38 - package-announce - Fedora Mailing-Lists |
MISC |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 39 Update: freerdp-2.11.1-1.fc39 - package-announce - Fedora Mailing-Lists |
MISC |
lists.fedoraproject.org |
|
| github.com/FreeRDP/FreeRDP/blob/63a2f65618748c12f79ff7450d46c6e194f2db76... |
MISC |
github.com |
|
| [SECURITY] Fedora 37 Update: freerdp-2.11.1-1.fc37 - package-announce - Fedora Mailing-Lists |
MISC |
lists.fedoraproject.org |
|
| [SECURITY] [DLA 3606-1] freerdp2 security update |
MISC |
lists.debian.org |
|
| Invalid offset validation leading to Out Of Bound Write · Advisory · FreeRDP/FreeRDP · GitHub |
MISC |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 199966 Ubuntu Security Notification for FreeRDP Vulnerabilities (USN-6522-1)
- 199988 Ubuntu Security Notification for FreeRDP Vulnerabilities (USN-6522-2)
- 284533 Fedora Security Update for freerdp (FEDORA-2023-5e6796cb83)
- 285270 Fedora Security Update for freerdp (FEDORA-2023-74108ca60d)
- 6000137 Debian Security Update for freerdp2 (DLA 3606-1)
- 710834 Gentoo Linux FreeRDP Multiple Vulnerabilities (GLSA 202401-16)