Lucene search

K
ubuntuUbuntuUSN-6752-1
HistoryApr 25, 2024 - 12:00 a.m.

FreeRDP vulnerabilities

2024-04-2500:00:00
ubuntu.com
15
freerdp
memory operations
ubuntu
denial of service
rdp client
malicious server

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

7.1

Confidence

Low

EPSS

0

Percentile

13.0%

Releases

  • Ubuntu 23.10
  • Ubuntu 22.04 LTS
  • Ubuntu 20.04 LTS

Packages

  • freerdp2 - RDP client for Windows Terminal Services

Details

It was discovered that FreeRDP incorrectly handled certain memory
operations. If a user were tricked into connecting to a malicious server, a
remote attacker could possibly use this issue to cause FreeRDP to crash,
resulting in a denial of service.

OSVersionArchitecturePackageVersionFilename
Ubuntu23.10noarchlibfreerdp2-2< 2.10.0+dfsg1-1.1ubuntu1.3UNKNOWN
Ubuntu23.10noarchfreerdp2-dev< 2.10.0+dfsg1-1.1ubuntu1.3UNKNOWN
Ubuntu23.10noarchfreerdp2-shadow-x11< 2.10.0+dfsg1-1.1ubuntu1.3UNKNOWN
Ubuntu23.10noarchfreerdp2-shadow-x11-dbgsym< 2.10.0+dfsg1-1.1ubuntu1.3UNKNOWN
Ubuntu23.10noarchfreerdp2-wayland< 2.10.0+dfsg1-1.1ubuntu1.3UNKNOWN
Ubuntu23.10noarchfreerdp2-wayland-dbgsym< 2.10.0+dfsg1-1.1ubuntu1.3UNKNOWN
Ubuntu23.10noarchfreerdp2-x11< 2.10.0+dfsg1-1.1ubuntu1.3UNKNOWN
Ubuntu23.10noarchfreerdp2-x11-dbgsym< 2.10.0+dfsg1-1.1ubuntu1.3UNKNOWN
Ubuntu23.10noarchlibfreerdp-client2-2< 2.10.0+dfsg1-1.1ubuntu1.3UNKNOWN
Ubuntu23.10noarchlibfreerdp-client2-2-dbgsym< 2.10.0+dfsg1-1.1ubuntu1.3UNKNOWN
Rows per page:
1-10 of 691

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

7.1

Confidence

Low

EPSS

0

Percentile

13.0%