Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-40576
HistoryAug 31, 2023 - 10:15 p.m.

Out-of-bounds

2023-08-3122:15:00
PRIOn knowledge base
www.prio-n.com
8
freerdp
rdp
out-of-bounds
read
vulnerability
rledecompress
apache license
upgrade
nvd

0.001 Low

EPSS

Percentile

21.4%

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versions are subject to an Out-Of-Bounds Read in the RleDecompress function. This Out-Of-Bounds Read occurs because FreeRDP processes the pbSrcBuffer variable without checking if it contains data of sufficient length. Insufficient data in the pbSrcBuffer variable may cause errors or crashes. This issue has been addressed in version 3.0.0-beta3. Users are advised to upgrade. There are no known workarounds for this issue.

CPENameOperatorVersion
freerdpeq3.0.0 beta1
freerdpeq3.0.0 beta2

0.001 Low

EPSS

Percentile

21.4%