Lucene search

K
alpinelinuxAlpine Linux Development TeamALPINE:CVE-2022-24882
HistoryApr 26, 2022 - 4:15 p.m.

CVE-2022-24882

2022-04-2616:15:00
Alpine Linux Development Team
security.alpinelinux.org
37
freerdp
remote desktop protocol
ntlm
authentication
vulnerability
patch
rdp server
unix

EPSS

0.004

Percentile

73.8%

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP). In versions prior to 2.7.0, NT LAN Manager (NTLM) authentication does not properly abort when someone provides and empty password value. This issue affects FreeRDP based RDP Server implementations. RDP clients are not affected. The vulnerability is patched in FreeRDP 2.7.0. There are currently no known workarounds.

OSVersionArchitecturePackageVersionFilename
Alpine3.15-communitynoarchfreerdp= 2.4.1-r0UNKNOWN