Name
CVE-2024-32658
Description
FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients prior to version 3.5.1 are vulnerable to out-of-bounds read. Version 3.5.1 contains a patch for the issue. No known workarounds are available.
Published Date
Updated Date
Workaround
-
Advisories
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5JL476WVJSIE7SBUKVJRVA6A52V2HOLZ/Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7SIS6NUNLUBOV4CPCSWKDE6T6C2W3WTR/Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PX3U6YPZQ7PEJBVKSBUOLWVH7DHROHY5/Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZKI4UISUXYNBPN4K6TIQKDRTIJ6CDCKJ/Third Party Advisory
https://oss-fuzz.com/testcase-detail/4852534033317888Permissions Required
https://oss-fuzz.com/testcase-detail/6196819496337408Permissions Required
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5JL476WVJSIE7SBUKVJRVA6A52V2HOLZ/Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7SIS6NUNLUBOV4CPCSWKDE6T6C2W3WTR/Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PX3U6YPZQ7PEJBVKSBUOLWVH7DHROHY5/Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZKI4UISUXYNBPN4K6TIQKDRTIJ6CDCKJ/Third Party Advisory
https://oss-fuzz.com/testcase-detail/4852534033317888Permissions Required
https://oss-fuzz.com/testcase-detail/6196819496337408Permissions Required
Analysis#
Vulnerability Ratings#
9.8
CVSSv31
9.8
CVSSv31
NaN
other
Others affected components#
Resolved with patches#
freerdp (yocto:kirkstone)
#
Title
Author
Resolve
1
fix offset error
akallabeth <akallabeth@posteo.net>
CVE-2024-32658
freerdp3 (yocto:scarthgap)
#
Title
Author
Resolve
1
fix offset error
akallabeth <akallabeth@posteo.net>
CVE-2024-32658