Medium severity5.3NVD Advisory· Published Oct 21, 2021· Updated Jun 17, 2026
CVE-2021-41160
CVE-2021-41160
Description
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. In affected versions a malicious server might trigger out of bound writes in a connected client. Connections using GDI or SurfaceCommands to send graphics updates to the client might send 0 width/height or out of bound rectangles to trigger out of bound writes. With 0 width or heigth the memory allocation will be 0 but the missing bounds checks allow writing to the pointer at this (not allocated) region. This issue has been patched in FreeRDP 2.4.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
15cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
- osv-coords9 versionspkg:rpm/almalinux/freerdppkg:rpm/almalinux/freerdp-develpkg:rpm/almalinux/freerdp-libspkg:rpm/almalinux/libwinprpkg:rpm/almalinux/libwinpr-develpkg:rpm/opensuse/freerdp&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/freerdp2&distro=openSUSE%20Tumbleweedpkg:rpm/suse/freerdp&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP4pkg:rpm/suse/freerdp&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP4
< 2:2.2.0-7.el8_5+ 8 more
- (no CPE)range: < 2:2.2.0-7.el8_5
- (no CPE)range: < 2:2.2.0-7.el8_5
- (no CPE)range: < 2:2.2.0-7.el8_5
- (no CPE)range: < 2:2.2.0-7.el8_5
- (no CPE)range: < 2:2.2.0-7.el8_5
- (no CPE)range: < 2.4.0-150400.3.6.1
- (no CPE)range: < 2.4.1-1.1
- (no CPE)range: < 2.4.0-150400.3.6.1
- (no CPE)range: < 2.4.0-150400.3.6.1
Patches
Vulnerability mechanics
References
7- github.com/FreeRDP/FreeRDP/security/advisories/GHSA-7c9r-6r2q-93qgnvdThird Party Advisory
- security.gentoo.org/glsa/202210-24nvdThird Party Advisory
- lists.debian.org/debian-lts-announce/2023/11/msg00010.htmlnvd
- lists.debian.org/debian-lts-announce/2025/02/msg00016.htmlnvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DWJXQOWKNR7O5HM2HFJOM4GBUFPTE3RG/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WIZUPVRGCWUDAPDOQVUGUIYUO7UWKMXX/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZXCR73EDVPLI6TRWRAWJCJ7OBYDKBB74/nvd
News mentions
0No linked articles in our index yet.