In FreeRDP less than or equal to 2.0.0, there is an out-of-bounds read in rfx_process_message_tileset. Invalid data fed to RFX decoder results in garbage on screen (as colors). This has been patched in 2.1.0.
The product reads data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-5mr4-28w3-rc84 | third party advisory patch |
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00080.html | third party advisory vendor advisory |
https://lists.debian.org/debian-lts-announce/2023/10/msg00008.html | third party advisory mailing list |