Lucene search

K
ubuntuUbuntuUSN-5734-1
HistoryNov 22, 2022 - 12:00 a.m.

FreeRDP vulnerabilities

2022-11-2200:00:00
ubuntu.com
28
freerdp
ubuntu
vulnerabilities
cve-2022-39282
cve-2022-39283
cve-2022-39316
cve-2022-39317
cve-2022-39318
cve-2022-39319
cve-2022-39320
cve-2022-39347
denial of service
sensitive information

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

6.8 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

61.9%

Releases

  • Ubuntu 22.10
  • Ubuntu 22.04 LTS
  • Ubuntu 20.04 LTS
  • Ubuntu 18.04 ESM

Packages

  • freerdp2 - RDP client for Windows Terminal Services

Details

It was discovered that FreeRDP incorrectly handled certain data lenghts. A
malicious server could use this issue to cause FreeRDP clients to crash,
resulting in a denial of service, or possibly obtain sensitive information.
This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu
22.04 LTS. (CVE-2022-39282, CVE-2022-39283)

It was discovered that FreeRDP incorrectly handled certain data lenghts. A
malicious server could use this issue to cause FreeRDP clients to crash,
resulting in a denial of service, or possibly obtain sensitive information.
(CVE-2022-39316, CVE-2022-39317, CVE-2022-39318, CVE-2022-39319,
CVE-2022-39320)

It was discovered that FreeRDP incorrectly handled certain path checks. A
malicious server could use this issue to cause FreeRDP clients to read
files outside of the shared directory. (CVE-2022-39347)

OSVersionArchitecturePackageVersionFilename
Ubuntu22.10noarchlibfreerdp-server2-2< 2.8.1+dfsg1-0ubuntu1.1UNKNOWN
Ubuntu22.10noarchfreerdp2-dev< 2.8.1+dfsg1-0ubuntu1.1UNKNOWN
Ubuntu22.10noarchfreerdp2-shadow-x11< 2.8.1+dfsg1-0ubuntu1.1UNKNOWN
Ubuntu22.10noarchfreerdp2-shadow-x11-dbgsym< 2.8.1+dfsg1-0ubuntu1.1UNKNOWN
Ubuntu22.10noarchfreerdp2-wayland< 2.8.1+dfsg1-0ubuntu1.1UNKNOWN
Ubuntu22.10noarchfreerdp2-wayland-dbgsym< 2.8.1+dfsg1-0ubuntu1.1UNKNOWN
Ubuntu22.10noarchfreerdp2-x11< 2.8.1+dfsg1-0ubuntu1.1UNKNOWN
Ubuntu22.10noarchfreerdp2-x11-dbgsym< 2.8.1+dfsg1-0ubuntu1.1UNKNOWN
Ubuntu22.10noarchlibfreerdp-client2-2< 2.8.1+dfsg1-0ubuntu1.1UNKNOWN
Ubuntu22.10noarchlibfreerdp-client2-2-dbgsym< 2.8.1+dfsg1-0ubuntu1.1UNKNOWN
Rows per page:
1-10 of 961

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

6.8 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

61.9%