FreeRDP is a free remote desktop protocol library and clients. All FreeRDP based clients when using the `/video` command line switch might read uninitialized data, decode it as audio/video and display the result. FreeRDP based server implementations are not affected. This issue has been patched in version 2.8.1. If you cannot upgrade do not use the `/video` switch.
References
Link | Resource |
---|---|
https://github.com/FreeRDP/FreeRDP/releases/tag/2.8.1 | Release Notes Third Party Advisory |
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-6cf9-3328-qrvh | Third Party Advisory |
https://security.gentoo.org/glsa/202210-24 | Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HEWWYMGWIMD4RDCOGHWMZXUMBGZHC5NW/ | Mailing List Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RLZCF7YHNC5BECDPEJNAZUYGNNM7NFME/ | Mailing List Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UDOTAOJBCZKREZJPT6VZ25GESI5T6RBG/ | Mailing List Third Party Advisory |
Information
Published : 2022-10-12 16:15
Updated : 2023-02-22 17:37
NVD link : CVE-2022-39283
Mitre link : CVE-2022-39283
JSON object : View
CWE
CWE-125
Out-of-bounds Read
Products Affected
freerdp
- freerdp
fedoraproject
- fedora