Allocation of Resources Without Limits or Throttling The advisory has been revoked - it doesn't affect any version of package freerdp3  (opens in a new tab)


Threat Intelligence

EPSS
1.17% (65th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UBUNTU2510-FREERDP3-15741034
  • published21 Mar 2026
  • disclosed23 Apr 2024

Introduced: 23 Apr 2024

CVE-2024-32660  (opens in a new tab)
CWE-770  (opens in a new tab)

Amendment

The Ubuntu security team deemed this advisory irrelevant for Ubuntu:25.10.

NVD Description

Note: Versions mentioned in the description apply only to the upstream freerdp3 package and not the freerdp3 package as distributed by Ubuntu.

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.5.1, a malicious server can crash the FreeRDP client by sending invalid huge allocation size. Version 3.5.1 contains a patch for the issue. No known workarounds are available.