FreeRDP.FreeRDP is vulnerable to Heap-based Buffer Overflow
70
High Risk
FreeRDP's Kerberos SSPI decrypts a peer-supplied GSS Wrap token during CredSSP/NLA and validates the rotation count and total length but never bounds the extra-count EC field. The unbounded EC value is used directly in the pointer arithmetic that locates the encrypted regions, moving those pointers past the end of the token buffer before the in-place decrypt runs. A malicious peer can trigger out-of-bounds reads and in-place writes on the heap during Kerberos decryption. The fix rejects tokens whose EC would move the message pointers past the token buffer.
You are affected if you are using a version that falls within the vulnerable range and you use Kerberos-based NLA/CredSSP authentication.
FreeRDP.FreeRDP is vulnerable to Heap-based Buffer Overflow in versions 3.0.0 - 3.29.0.
Upgrade the FreeRDP.FreeRDP library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant