Name
CVE-2024-32661
Description
FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients prior to version 3.5.1 are vulnerable to a possible `NULL` access and crash. Version 3.5.1 contains a patch for the issue. No known workarounds are available.
Published Date
Updated Date
Workaround
-
Advisories
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5JL476WVJSIE7SBUKVJRVA6A52V2HOLZ/Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7SIS6NUNLUBOV4CPCSWKDE6T6C2W3WTR/Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PX3U6YPZQ7PEJBVKSBUOLWVH7DHROHY5/Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZKI4UISUXYNBPN4K6TIQKDRTIJ6CDCKJ/Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5JL476WVJSIE7SBUKVJRVA6A52V2HOLZ/Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7SIS6NUNLUBOV4CPCSWKDE6T6C2W3WTR/Third Party Advisory
Analysis#
Vulnerability Ratings#
7.5
CVSSv31
7.5
CVSSv31
NaN
other
Others affected components#
Resolved with patches#
freerdp (buildroot:2025.02.x)
#
Title
Author
Resolve
1
[core,info] fix missing check in rdp_write_logon_info_v1
akallabeth <akallabeth@posteo.net>
CVE-2024-32661
freerdp (buildroot:master)
#
Title
Author
Resolve
1
[core,info] fix missing check in rdp_write_logon_info_v1
akallabeth <akallabeth@posteo.net>
CVE-2024-32661
freerdp (yocto:master)
#
Title
Author
Resolve
1
[core,info] fix missing check in rdp_write_logon_info_v1
akallabeth <akallabeth@posteo.net>
CVE-2024-32661
freerdp (yocto:scarthgap)
#
Title
Author
Resolve
1
[core,info] fix missing check in rdp_write_logon_info_v1
akallabeth <akallabeth@posteo.net>
CVE-2024-32661
freerdp3 (yocto:scarthgap)
#
Title
Author
Resolve
1
fix missing check in rdp_write_logon_info_v1
akallabeth <akallabeth@posteo.net>
CVE-2024-32661