Lucene search

K
ubuntucveUbuntu.comUB:CVE-2024-32660
HistoryApr 23, 2024 - 12:00 a.m.

CVE-2024-32660

2024-04-2300:00:00
ubuntu.com
ubuntu.com
7
cve-2024-32660
freerdp
remote desktop protocol
security vulnerability
patch
crash
malicious server
allocation size
unix

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.0004 Low

EPSS

Percentile

10.5%

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to
version 3.5.1, a malicious server can crash the FreeRDP client by sending
invalid huge allocation size. Version 3.5.1 contains a patch for the issue.
No known workarounds are available.

Notes

Author Note
Priority reason: FreeRDP developers have rated this as being a low severity issue
OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchfreerdp< anyUNKNOWN
ubuntu16.04noarchfreerdp< anyUNKNOWN
ubuntu18.04noarchfreerdp2< anyUNKNOWN
ubuntu20.04noarchfreerdp2< 2.6.1+dfsg1-0ubuntu0.20.04.2UNKNOWN
ubuntu22.04noarchfreerdp2< 2.6.1+dfsg1-3ubuntu2.7UNKNOWN
ubuntu23.10noarchfreerdp2< 2.10.0+dfsg1-1.1ubuntu1.3UNKNOWN
ubuntu24.04noarchfreerdp2< anyUNKNOWN
ubuntu24.04noarchfreerdp3< 3.5.1+dfsg1-0ubuntu1UNKNOWN

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.0004 Low

EPSS

Percentile

10.5%