Lucene search

K
ubuntuUbuntuUSN-6522-1
HistoryNov 29, 2023 - 12:00 a.m.

FreeRDP vulnerabilities

2023-11-2900:00:00
ubuntu.com
22
freerdp
vulnerabilities
ubuntu
drive redirection
surface updates
remote attack
denial of service
sensitive information
arbitrary code

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

7.8 High

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

52.7%

Releases

  • Ubuntu 23.10
  • Ubuntu 23.04
  • Ubuntu 22.04 LTS
  • Ubuntu 20.04 LTS

Packages

  • freerdp2 - RDP client for Windows Terminal Services

Details

It was discovered that FreeRDP incorrectly handled drive redirection. If a
user were tricked into connection to a malicious server, a remote attacker
could use this issue to cause FreeRDP to crash, resulting in a denial of
service, or possibly obtain sensitive information. (CVE-2022-41877)

It was discovered that FreeRDP incorrectly handled certain surface updates.
A remote attacker could use this issue to cause FreeRDP to crash, resulting
in a denial of service, or possibly execute arbitrary code.
(CVE-2023-39352, CVE-2023-39356)

OSVersionArchitecturePackageVersionFilename
Ubuntu23.10noarchlibfreerdp2-2< 2.10.0+dfsg1-1.1ubuntu1.1UNKNOWN
Ubuntu23.10noarchfreerdp2-dev< 2.10.0+dfsg1-1.1ubuntu1.1UNKNOWN
Ubuntu23.10noarchfreerdp2-shadow-x11< 2.10.0+dfsg1-1.1ubuntu1.1UNKNOWN
Ubuntu23.10noarchfreerdp2-shadow-x11-dbgsym< 2.10.0+dfsg1-1.1ubuntu1.1UNKNOWN
Ubuntu23.10noarchfreerdp2-wayland< 2.10.0+dfsg1-1.1ubuntu1.1UNKNOWN
Ubuntu23.10noarchfreerdp2-wayland-dbgsym< 2.10.0+dfsg1-1.1ubuntu1.1UNKNOWN
Ubuntu23.10noarchfreerdp2-x11< 2.10.0+dfsg1-1.1ubuntu1.1UNKNOWN
Ubuntu23.10noarchfreerdp2-x11-dbgsym< 2.10.0+dfsg1-1.1ubuntu1.1UNKNOWN
Ubuntu23.10noarchlibfreerdp-client2-2< 2.10.0+dfsg1-1.1ubuntu1.1UNKNOWN
Ubuntu23.10noarchlibfreerdp-client2-2-dbgsym< 2.10.0+dfsg1-1.1ubuntu1.1UNKNOWN
Rows per page:
1-10 of 961

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

7.8 High

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

52.7%