CVE-2024-32460
Published: 23 April 2024
FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based based clients using `/bpp:32` legacy `GDI` drawing path with a version of FreeRDP prior to 3.5.0 or 2.11.6 are vulnerable to out-of-bounds read. Versions 3.5.0 and 2.11.6 patch the issue. As a workaround, use modern drawing paths (e.g. `/rfx` or `/gfx` options). The workaround requires server side support.
Notes
Author | Note |
---|---|
Priority reason: FreeRDP developers have rated this as being a low severity issue |
Priority
Status
Package | Release | Status |
---|---|---|
freerdp Launchpad, Ubuntu, Debian |
bionic |
Needs triage
|
focal |
Does not exist
|
|
jammy |
Does not exist
|
|
mantic |
Does not exist
|
|
noble |
Does not exist
|
|
upstream |
Needs triage
|
|
xenial |
Needs triage
|
|
freerdp2 Launchpad, Ubuntu, Debian |
bionic |
Needs triage
|
focal |
Released
(2.6.1+dfsg1-0ubuntu0.20.04.1)
|
|
jammy |
Released
(2.6.1+dfsg1-3ubuntu2.6)
|
|
mantic |
Released
(2.10.0+dfsg1-1.1ubuntu1.2)
|
|
noble |
Needed
|
|
upstream |
Released
(2.11.6)
|
|
Patches: upstream: https://github.com/FreeRDP/FreeRDP/commit/18cef378eae2b63a1a750da242f00da12b5b3881 |
||
freerdp3 Launchpad, Ubuntu, Debian |
focal |
Does not exist
|
jammy |
Does not exist
|
|
mantic |
Does not exist
|
|
noble |
Released
(3.5.0+dfsg1-0ubuntu1)
|
|
upstream |
Released
(3.5.0)
|
References
- https://www.cve.org/CVERecord?id=CVE-2024-32460
- https://www.freerdp.com/2024/04/17/2_11_6-release
- https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-4rr8-gr65-vqrr
- https://github.com/FreeRDP/FreeRDP/pull/10077
- https://github.com/FreeRDP/FreeRDP/releases/tag/2.11.6
- https://github.com/FreeRDP/FreeRDP/releases/tag/3.5.0
- https://ubuntu.com/security/notices/USN-6749-1
- NVD
- Launchpad
- Debian