Out-of-bounds Read Affecting freerdp package, versions <2.4.0-150400.3.18.1
Threat Intelligence
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-SLES154-FREERDP-3320022
- published 15 Feb 2023
- disclosed 13 Feb 2023
Introduced: 13 Feb 2023
CVE-2022-39316 Open this link in a new tabHow to fix?
Upgrade SLES:15.4 freerdp to version 2.4.0-150400.3.18.1 or higher.
NVD Description
Note: Versions mentioned in the description apply only to the upstream freerdp package and not the freerdp package as distributed by SLES.
See How to fix? for SLES:15.4 relevant fixed versions and status.
FreeRDP is a free remote desktop protocol library and clients. In affected versions there is an out of bound read in ZGFX decoder component of FreeRDP. A malicious server can trick a FreeRDP based client to read out of bound data and try to decode it likely resulting in a crash. This issue has been addressed in the 2.9.0 release. Users are advised to upgrade.
References
- https://www.suse.com/security/cve/CVE-2022-39316.html
- https://bugzilla.suse.com/1205512
- https://github.com/FreeRDP/FreeRDP/commit/e865c24efc40ebc52e75979c94cdd4ee2c1495b0
- https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-5w4j-mrrh-jjrm
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YGQN3OWQNHSMWKOF4D35PF5ASKNLC74B/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UDOTAOJBCZKREZJPT6VZ25GESI5T6RBG/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UDOTAOJBCZKREZJPT6VZ25GESI5T6RBG/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YGQN3OWQNHSMWKOF4D35PF5ASKNLC74B/
- https://lists.debian.org/debian-lts-announce/2023/11/msg00010.html
- https://security.gentoo.org/glsa/202401-16