FreeRDP.FreeRDP is vulnerable to NULL Pointer Dereference
37
Low Risk
The smartcard cache request decoders accept a NULL NDR pointer for the lookup name in the read-cache and write-cache device controls and return success with a valid card identifier. When smartcard emulation is enabled, the emulated cache sink calls strlen on that NULL lookup name, terminating the client process. A peer-controlled smartcard cache request with a NULL lookup-name pointer reaches this path and crashes the client. The fix rejects a NULL lookup name during decoding and in the emulated cache handlers.
You are affected if you are using a version that falls within the vulnerable range and you enable smartcard redirection with the smartcard emulation backend.
FreeRDP.FreeRDP is vulnerable to NULL Pointer Dereference in versions 0.0.1 - 3.28.0.
Upgrade the FreeRDP.FreeRDP library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant