In FreeRDP after 1.0 and before 2.0.0, there is an out-of-bound read in in update_read_bitmap_data that allows client memory to be read to an image buffer. The result displayed on screen as colour.
The product reads data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-3x39-248q-f4q6 | third party advisory |
https://github.com/FreeRDP/FreeRDP/issues/6005 | third party advisory exploit |
https://github.com/FreeRDP/FreeRDP/commit/f8890a645c221823ac133dbf991f8a65ae50d637 | third party advisory patch |
https://usn.ubuntu.com/4379-1/ | third party advisory vendor advisory |
https://usn.ubuntu.com/4382-1/ | third party advisory vendor advisory |
https://lists.debian.org/debian-lts-announce/2020/08/msg00054.html | third party advisory mailing list |
https://lists.debian.org/debian-lts-announce/2023/10/msg00008.html | third party advisory mailing list |