VYPR
Unrated severityNVD Advisory· Published Aug 31, 2023· Updated Feb 13, 2025

Use-After-Free in FreeRDP

CVE-2023-40187

Description

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versions of the 3.x beta branch are subject to a Use-After-Free issue in the avc420_ensure_buffer and avc444_ensure_buffer functions. If the value of piDstSize[x] is 0, ppYUVDstData[x] will be freed. However, in this case ppYUVDstData[x] will not have been updated which leads to a Use-After-Free vulnerability. This issue has been addressed in version 3.0.0-beta3. Users of the 3.x beta releases are advised to upgrade. There are no known workarounds for this vulnerability.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Freerdp/Freerdpllm-fuzzy2 versions
    <3.0.0-beta3+ 1 more
    • (no CPE)range: <3.0.0-beta3
    • (no CPE)range: >= 3.0.0-beta1, < 3.0.0-beta3

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.