yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2024-32661
Component Overview
Vulnerability Overview
Name
CVE-2024-32661
Source
NVD (
link
)
Debian (
link
)
Description
FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients prior to version 3.5.1 are vulnerable to a possible `NULL` access and crash. Version 3.5.1 contains a patch for the issue. No known workarounds are available.
CWEs
CWE-476
CWE-476
Published Date
Apr 23, 2024
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://github.com/FreeRDP/FreeRDP/commit/71e463e31b4d69f4022d36bfc814592f56600793
Patch
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-p5m5-342g-pv9m
Vendor Advisory
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5JL476WVJSIE7SBUKVJRVA6A52V2HOLZ/
Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7SIS6NUNLUBOV4CPCSWKDE6T6C2W3WTR/
Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PX3U6YPZQ7PEJBVKSBUOLWVH7DHROHY5/
Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZKI4UISUXYNBPN4K6TIQKDRTIJ6CDCKJ/
Third Party Advisory
https://github.com/FreeRDP/FreeRDP/commit/71e463e31b4d69f4022d36bfc814592f56600793
Patch
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-p5m5-342g-pv9m
Vendor Advisory
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5JL476WVJSIE7SBUKVJRVA6A52V2HOLZ/
Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7SIS6NUNLUBOV4CPCSWKDE6T6C2W3WTR/
Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PX3U6YPZQ7PEJBVKSBUOLWVH7DHROHY5/
Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZKI4UISUXYNBPN4K6TIQKDRTIJ6CDCKJ/
Third Party Advisory
Analysis
#
Affected Component
Analysis
freerdp
Exploitable
Vulnerability Ratings
#
7.5
CVSSv31
7.5
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
freerdp
buildroot
2025.02.x
2.11.8
Patched
freerdp
buildroot
master
2.11.8
Patched
freerdp
yocto
master
2.11.8
Patched
freerdp3
yocto
master
3.26.0
Patched
freerdp
yocto
scarthgap
2.11.8
Patched
freerdp3
yocto
scarthgap
3.4.0
Patched
Resolved with patches
#
freerdp (buildroot:2025.02.x)
#
Title
Author
Resolve
1
[core,info] fix missing check in rdp_write_logon_info_v1
akallabeth <akallabeth@posteo.net>
CVE-2024-32661
freerdp (buildroot:master)
#
Title
Author
Resolve
1
[core,info] fix missing check in rdp_write_logon_info_v1
akallabeth <akallabeth@posteo.net>
CVE-2024-32661
freerdp (yocto:master)
#
Title
Author
Resolve
1
[core,info] fix missing check in rdp_write_logon_info_v1
akallabeth <akallabeth@posteo.net>
CVE-2024-32661
freerdp (yocto:scarthgap)
#
Title
Author
Resolve
1
[core,info] fix missing check in rdp_write_logon_info_v1
akallabeth <akallabeth@posteo.net>
CVE-2024-32661
freerdp3 (yocto:scarthgap)
#
Title
Author
Resolve
1
fix missing check in rdp_write_logon_info_v1
akallabeth <akallabeth@posteo.net>
CVE-2024-32661