FreeRDP.FreeRDP is vulnerable to Out-of-bounds Read
21
Low Risk
The UVC H.264 extension-unit lookup in the camera redirection client walks USB video-control extra descriptors and casts each entry to a full descriptor structure after checking only its type and subtype. A short four-byte extension-unit descriptor satisfies those checks, so the code reads a 16-byte GUID field that lies past the end of the descriptor buffer. A malicious local USB video device can trigger a heap out-of-bounds read during camera stream setup. The fix validates the remaining buffer length before reading the descriptor fields.
You are affected if you are using a version that falls within the vulnerable range and you use the rdpecam camera redirection path with an untrusted local USB video device.
FreeRDP.FreeRDP is vulnerable to Out-of-bounds Read in versions 0.0.1 - 3.28.0.
Upgrade the FreeRDP.FreeRDP library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant