FreeRDP.FreeRDP is vulnerable to Out-of-bounds Read
54
Medium Risk
The glyph cache update handler processes a GLYPH_FRAGMENT_ADD order by reading a one-byte declared fragment size from server-controlled data without checking that the declared size fits in the received buffer. The cache store then allocates and copies that many bytes from the fragment pointer, reading past the end of a short allocation. A malicious RDP server can cause a client-side heap out-of-bounds read and crash. The fix validates the declared fragment size against the remaining buffer before copying.
You are affected if you are using a version that falls within the vulnerable range.
FreeRDP.FreeRDP is vulnerable to Out-of-bounds Read in versions 0.0.1 - 3.28.0.
Upgrade the FreeRDP.FreeRDP library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant