VYPR

rpm package

almalinux/libwinpr-devel

pkg:rpm/almalinux/libwinpr-devel

Vulnerabilities (91)

  • CVE-2022-39319MedNov 16, 2022
    affected < 2:2.4.1-5.el9fixed 2:2.4.1-5.el9

    FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing input length validation in the `urbdrc` channel. A malicious server can trick a FreeRDP based client to read out of bound data and send it back to the server. This issue has be

  • CVE-2022-39318MedNov 16, 2022
    affected < 2:2.4.1-5.el9fixed 2:2.4.1-5.el9

    FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing input validation in `urbdrc` channel. A malicious server can trick a FreeRDP based client to crash with division by zero. This issue has been addressed in version 2.9.0. All us

  • CVE-2022-39317MedNov 16, 2022
    affected < 2:2.4.1-5.el9fixed 2:2.4.1-5.el9

    FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing a range check for input offset index in ZGFX decoder. A malicious server can trick a FreeRDP based client to read out of bound data and try to decode it. This issue has been ad

  • CVE-2022-41877MedNov 16, 2022
    affected < 2:2.4.1-5.el9fixed 2:2.4.1-5.el9

    FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing input length validation in `drive` channel. A malicious server can trick a FreeRDP based client to read out of bound data and send it back to the server. This issue has been ad

  • CVE-2022-39347LowNov 16, 2022
    affected < 2:2.4.1-5.el9fixed 2:2.4.1-5.el9

    FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing path canonicalization and base path check for `drive` channel. A malicious server can trick a FreeRDP based client to read files outside the shared directory. This issue has be

  • CVE-2022-39320MedNov 16, 2022
    affected < 2:2.4.1-5.el9fixed 2:2.4.1-5.el9

    FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP may attempt integer addition on too narrow types leads to allocation of a buffer too small holding the data written. A malicious server can trick a FreeRDP based client to read out of boun

  • CVE-2022-39316MedNov 16, 2022
    affected < 2:2.4.1-5.el9fixed 2:2.4.1-5.el9

    FreeRDP is a free remote desktop protocol library and clients. In affected versions there is an out of bound read in ZGFX decoder component of FreeRDP. A malicious server can trick a FreeRDP based client to read out of bound data and try to decode it likely resulting in a crash.

  • CVE-2022-39283MedOct 12, 2022
    affected < 2:2.4.1-5.el9fixed 2:2.4.1-5.el9

    FreeRDP is a free remote desktop protocol library and clients. All FreeRDP based clients when using the `/video` command line switch might read uninitialized data, decode it as audio/video and display the result. FreeRDP based server implementations are not affected. This issue h

  • CVE-2022-39282LowOct 12, 2022
    affected < 2:2.4.1-5.el9fixed 2:2.4.1-5.el9

    FreeRDP is a free remote desktop protocol library and clients. FreeRDP based clients on unix systems using `/parallel` command line switch might read uninitialized data and send it to the server the client is currently connected to. FreeRDP based server implementations are not af

  • CVE-2021-41160MedOct 21, 2021
    affected < 2:2.2.0-7.el8_5fixed 2:2.2.0-7.el8_5

    FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. In affected versions a malicious server might trigger out of bound writes in a connected client. Connections using GDI or SurfaceCommands to send graphics updates to the clie

  • CVE-2021-41159MedOct 21, 2021
    affected < 2:2.2.0-7.el8_5fixed 2:2.2.0-7.el8_5

    FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. All FreeRDP clients prior to version 2.4.1 using gateway connections (`/gt:rpc`) fail to validate input data. A malicious gateway might allow client memory to be written out

Page 5 of 5