Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-40187
HistoryAug 31, 2023 - 10:15 p.m.

Double free

2023-08-3122:15:00
PRIOn knowledge base
www.prio-n.com
3
freerdp
remote desktop protocol
use-after-free
avc functions
apache license
upgrade
nvd

9.6 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

29.9%

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versions of the 3.x beta branch are subject to a Use-After-Free issue in the avc420_ensure_buffer and avc444_ensure_buffer functions. If the value of piDstSize[x] is 0, ppYUVDstData[x] will be freed. However, in this case ppYUVDstData[x] will not have been updated which leads to a Use-After-Free vulnerability. This issue has been addressed in version 3.0.0-beta3. Users of the 3.x beta releases are advised to upgrade. There are no known workarounds for this vulnerability.

CPENameOperatorVersion
freerdpeq3.0.0 beta1
freerdpeq3.0.0 beta2

9.6 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

29.9%