Beveiligingsadvies

CVE-2022-39317

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2022-11-16 00:00:00
Laatst bijgewerkt 2025-04-23 16:37:08
Toegewezen door GitHub_M
CVSS-score 4.6
Status PUBLISHED

Beschrijving

FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing a range check for input offset index in ZGFX decoder. A malicious server can trick a FreeRDP based client to read out of bound data and try to decode it. This issue has been addressed in version 2.9.0. There are no known workarounds for this issue.