rpm package
almalinux/freerdp
pkg:rpm/almalinux/freerdp
Vulnerabilities (91)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2022-39319 | Med | 4.6 | < 2:2.4.1-5.el9 | 2:2.4.1-5.el9 | Nov 16, 2022 | FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing input length validation in the `urbdrc` channel. A malicious server can trick a FreeRDP based client to read out of bound data and send it back to the server. This issue has be | |
| CVE-2022-39318 | Med | 4.8 | < 2:2.4.1-5.el9 | 2:2.4.1-5.el9 | Nov 16, 2022 | FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing input validation in `urbdrc` channel. A malicious server can trick a FreeRDP based client to crash with division by zero. This issue has been addressed in version 2.9.0. All us | |
| CVE-2022-39317 | Med | 4.6 | < 2:2.4.1-5.el9 | 2:2.4.1-5.el9 | Nov 16, 2022 | FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing a range check for input offset index in ZGFX decoder. A malicious server can trick a FreeRDP based client to read out of bound data and try to decode it. This issue has been ad | |
| CVE-2022-41877 | Med | 4.6 | < 2:2.4.1-5.el9 | 2:2.4.1-5.el9 | Nov 16, 2022 | FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing input length validation in `drive` channel. A malicious server can trick a FreeRDP based client to read out of bound data and send it back to the server. This issue has been ad | |
| CVE-2022-39347 | Low | 2.6 | < 2:2.4.1-5.el9 | 2:2.4.1-5.el9 | Nov 16, 2022 | FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing path canonicalization and base path check for `drive` channel. A malicious server can trick a FreeRDP based client to read files outside the shared directory. This issue has be | |
| CVE-2022-39320 | Med | 5.5 | < 2:2.4.1-5.el9 | 2:2.4.1-5.el9 | Nov 16, 2022 | FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP may attempt integer addition on too narrow types leads to allocation of a buffer too small holding the data written. A malicious server can trick a FreeRDP based client to read out of boun | |
| CVE-2022-39316 | Med | 4.8 | < 2:2.4.1-5.el9 | 2:2.4.1-5.el9 | Nov 16, 2022 | FreeRDP is a free remote desktop protocol library and clients. In affected versions there is an out of bound read in ZGFX decoder component of FreeRDP. A malicious server can trick a FreeRDP based client to read out of bound data and try to decode it likely resulting in a crash. | |
| CVE-2022-39283 | Med | 5.9 | < 2:2.4.1-5.el9 | 2:2.4.1-5.el9 | Oct 12, 2022 | FreeRDP is a free remote desktop protocol library and clients. All FreeRDP based clients when using the `/video` command line switch might read uninitialized data, decode it as audio/video and display the result. FreeRDP based server implementations are not affected. This issue h | |
| CVE-2022-39282 | Low | 3.5 | < 2:2.4.1-5.el9 | 2:2.4.1-5.el9 | Oct 12, 2022 | FreeRDP is a free remote desktop protocol library and clients. FreeRDP based clients on unix systems using `/parallel` command line switch might read uninitialized data and send it to the server the client is currently connected to. FreeRDP based server implementations are not af | |
| CVE-2021-41160 | Med | 5.3 | < 2:2.2.0-7.el8_5 | 2:2.2.0-7.el8_5 | Oct 21, 2021 | FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. In affected versions a malicious server might trigger out of bound writes in a connected client. Connections using GDI or SurfaceCommands to send graphics updates to the clie | |
| CVE-2021-41159 | Med | 5.8 | < 2:2.2.0-7.el8_5 | 2:2.2.0-7.el8_5 | Oct 21, 2021 | FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. All FreeRDP clients prior to version 2.4.1 using gateway connections (`/gt:rpc`) fail to validate input data. A malicious gateway might allow client memory to be written out |
- affected < 2:2.4.1-5.el9fixed 2:2.4.1-5.el9
FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing input length validation in the `urbdrc` channel. A malicious server can trick a FreeRDP based client to read out of bound data and send it back to the server. This issue has be
- affected < 2:2.4.1-5.el9fixed 2:2.4.1-5.el9
FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing input validation in `urbdrc` channel. A malicious server can trick a FreeRDP based client to crash with division by zero. This issue has been addressed in version 2.9.0. All us
- affected < 2:2.4.1-5.el9fixed 2:2.4.1-5.el9
FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing a range check for input offset index in ZGFX decoder. A malicious server can trick a FreeRDP based client to read out of bound data and try to decode it. This issue has been ad
- affected < 2:2.4.1-5.el9fixed 2:2.4.1-5.el9
FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing input length validation in `drive` channel. A malicious server can trick a FreeRDP based client to read out of bound data and send it back to the server. This issue has been ad
- affected < 2:2.4.1-5.el9fixed 2:2.4.1-5.el9
FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing path canonicalization and base path check for `drive` channel. A malicious server can trick a FreeRDP based client to read files outside the shared directory. This issue has be
- affected < 2:2.4.1-5.el9fixed 2:2.4.1-5.el9
FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP may attempt integer addition on too narrow types leads to allocation of a buffer too small holding the data written. A malicious server can trick a FreeRDP based client to read out of boun
- affected < 2:2.4.1-5.el9fixed 2:2.4.1-5.el9
FreeRDP is a free remote desktop protocol library and clients. In affected versions there is an out of bound read in ZGFX decoder component of FreeRDP. A malicious server can trick a FreeRDP based client to read out of bound data and try to decode it likely resulting in a crash.
- affected < 2:2.4.1-5.el9fixed 2:2.4.1-5.el9
FreeRDP is a free remote desktop protocol library and clients. All FreeRDP based clients when using the `/video` command line switch might read uninitialized data, decode it as audio/video and display the result. FreeRDP based server implementations are not affected. This issue h
- affected < 2:2.4.1-5.el9fixed 2:2.4.1-5.el9
FreeRDP is a free remote desktop protocol library and clients. FreeRDP based clients on unix systems using `/parallel` command line switch might read uninitialized data and send it to the server the client is currently connected to. FreeRDP based server implementations are not af
- affected < 2:2.2.0-7.el8_5fixed 2:2.2.0-7.el8_5
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. In affected versions a malicious server might trigger out of bound writes in a connected client. Connections using GDI or SurfaceCommands to send graphics updates to the clie
- affected < 2:2.2.0-7.el8_5fixed 2:2.2.0-7.el8_5
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. All FreeRDP clients prior to version 2.4.1 using gateway connections (`/gt:rpc`) fail to validate input data. A malicious gateway might allow client memory to be written out
Page 5 of 5