Security Advisory

CVE-2022-39317

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2022-11-16 00:00:00
Last updated 2025-04-23 16:37:08
Assigner GitHub_M
State PUBLISHED

Description

FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing a range check for input offset index in ZGFX decoder. A malicious server can trick a FreeRDP based client to read out of bound data and try to decode it. This issue has been addressed in version 2.9.0. There are no known workarounds for this issue.