CVE-2022-39317
—CVSS 3.1
4.6 medium
EPSS
<1%p49
Published
()
Modified
Description
FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing a range check for input offset index in ZGFX decoder. A malicious server can trick a FreeRDP based client to read out of bound data and try to decode it. This issue has been addressed in version 2.9.0. There are no known workarounds for this issue.
- Vendors
- freerdpfedoraproject
- Products
- freerdp, fedora
- Weakness
- CWE-125
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L
In the news0 stories
No ingested article mentions this CVE yet.