VYPR

rpm package

opensuse/freerdp&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/freerdp&distro=openSUSE%20Tumbleweed

Vulnerabilities (92)

  • CVE-2024-32460HigApr 22, 2024
    affected < 3.5.1-1.1fixed 3.5.1-1.1

    FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based based clients using `/bpp:32` legacy `GDI` drawing path with a version of FreeRDP prior to 3.5.0 or 2.11.6 are vulnerable to out-of-bounds read. Versions 3.5.0 and 2.11.6 patch the issue. As a workarou

  • CVE-2024-32459CriApr 22, 2024
    affected < 3.5.1-1.1fixed 3.5.1-1.1

    FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients and servers that use a version of FreeRDP prior to 3.5.0 or 2.11.6 are vulnerable to out-of-bounds read. Versions 3.5.0 and 2.11.6 patch the issue. No known workarounds are available.

  • CVE-2024-32458CriApr 22, 2024
    affected < 3.5.1-1.1fixed 3.5.1-1.1

    FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients that use a version of FreeRDP prior to 3.5.0 or 2.11.6 are vulnerable to out-of-bounds read. Versions 3.5.0 and 2.11.6 patch the issue. As a workaround, use `/gfx` or `/rfx` modes (on by defaul

  • CVE-2024-32041CriApr 22, 2024
    affected < 3.5.1-1.1fixed 3.5.1-1.1

    FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients that use a version of FreeRDP prior to 3.5.0 or 2.11.6 are vulnerable to out-of-bounds read. Versions 3.5.0 and 2.11.6 patch the issue. As a workaround, deactivate `/gfx` (on by default, set `/

  • CVE-2024-32040HigApr 22, 2024
    affected < 3.5.1-1.1fixed 3.5.1-1.1

    FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients that use a version of FreeRDP prior to 3.5.0 or 2.11.6 and have connections to servers using the `NSC` codec are vulnerable to integer underflow. Versions 3.5.0 and 2.11.6 patch the issue. As a

  • CVE-2024-32039CriApr 22, 2024
    affected < 3.5.1-1.1fixed 3.5.1-1.1

    FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients using a version of FreeRDP prior to 3.5.0 or 2.11.6 are vulnerable to integer overflow and out-of-bounds write. Versions 3.5.0 and 2.11.6 patch the issue. As a workaround, do not use `/gfx` opt

  • CVE-2024-22211LowJan 19, 2024
    affected < 3.21.0-2.1fixed 3.21.0-2.1

    FreeRDP is a set of free and open source remote desktop protocol library and clients. In affected versions an integer overflow in `freerdp_bitmap_planar_context_reset` leads to heap-buffer overflow. This affects FreeRDP based clients. FreeRDP based server implementations and prox

  • CVE-2023-40576MedAug 31, 2023
    affected < 3.4.0-1.1fixed 3.4.0-1.1

    FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versions are subject to an Out-Of-Bounds Read in the `RleDecompress` function. This Out-Of-Bounds Read occurs because FreeRDP processes the `pbSrcBuffer` variable wi

  • CVE-2023-40575MedAug 31, 2023
    affected < 3.4.0-1.1fixed 3.4.0-1.1

    FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versions are subject to an Out-Of-Bounds Read in the `general_YUV444ToRGB_8u_P3AC4R_BGRX` function. This issue is likely down to insufficient data for the `pSrc` var

  • CVE-2023-40574MedAug 31, 2023
    affected < 3.4.0-1.1fixed 3.4.0-1.1

    FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versions are subject to an Out-Of-Bounds Write in the `writePixelBGRX` function. This issue is likely down to incorrect calculations of the `nHeight` and `srcStep` v

  • CVE-2014-0250Nov 16, 2014
    affected < 2.0.0~git.1463131968.4e66df7-2.5fixed 2.0.0~git.1463131968.4e66df7-2.5

    Multiple integer overflows in client/X11/xf_graphics.c in FreeRDP allow remote attackers to have an unspecified impact via the width and height to the (1) xf_Pointer_New or (2) xf_Bitmap_Decompress function, which causes an incorrect amount of memory to be allocated.

  • CVE-2014-0791Jan 3, 2014
    affected < 2.0.0~git.1463131968.4e66df7-2.5fixed 2.0.0~git.1463131968.4e66df7-2.5

    Integer overflow in the license_read_scope_list function in libfreerdp/core/license.c in FreeRDP through 1.0.2 allows remote RDP servers to cause a denial of service (application crash) or possibly have unspecified other impact via a large ScopeCount value in a Scope List in a Se

Page 5 of 5