Lucene search

K
redhatcveRedhat.comRH:CVE-2022-39317
HistoryNov 17, 2022 - 1:56 p.m.

CVE-2022-39317

2022-11-1713:56:42
redhat.com
access.redhat.com
20
cve-2022-39317
freerdp
zgfx decoder
out-of-bounds read
vulnerability
missing range check
input offset index
malicious server
crash

CVSS3

4.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L

EPSS

0.001

Percentile

48.9%

An out-of-bounds read vulnerability was discovered in FreeRDP due to missing a range check for input offset index in the ZGFX decoder. A malicious server can trick a FreeRDP based client to read out-of-bound data and try to decode it, resulting in a crash.

CVSS3

4.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L

EPSS

0.001

Percentile

48.9%