Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Fedora 39: FEDORA-2023-74108ca60d Critical: FreeRDP RDP Client Update

fedora
Calendar Grey September 21, 2023
Dist Fedora Esm H88
The latest Fedora 39 update includes a critical patch for FreeRDP 2.11.1, fixing essential security vulnerabilities in RDP client functionality for better system safety
Update to 2.11.1 ---- Update to 2.11.0 (CVE-2023-39350, CVE-2023-39351, CVE-2023-39352, CVE-2023-39353, CVE-2023-39354, CVE-2023-39356, CVE-2023-40181, CVE-2023-40186, CVE-2023-401...

Summary

The xfreerdp & wlfreerdp Remote Desktop Protocol (RDP) clients from the FreeRDP

project.

xfreerdp & wlfreerdp can connect to RDP servers such as Microsoft Windows

machines, xrdp and VirtualBox.

Update Information:

Update to 2.11.1 ---- Update to 2.11.0 (CVE-2023-39350, CVE-2023-39351, CVE-2023-39352, CVE-2023-39353, CVE-2023-39354, CVE-2023-39356, CVE-2023-40181, CVE-2023-40186, CVE-2023-40188, CVE-2023-40567, CVE-2023-40569 and CVE-2023-40589).

Change Log

* Tue Sep 5 2023 Ondrej Holy - 2:2.11.1-1 - Update to 2.11.1. * Fri Sep 1 2023 Ondrej Holy - 2:2.11.0-1 - Update to 2.11.0 (CVE-2023-39350, CVE-2023-39351, CVE-2023-39352, CVE-2023-39353, CVE-2023-39354, CVE-2023-39356, CVE-2023-40181, CVE-2023-40186, CVE-2023-40188, CVE-2023-40567, CVE-2023-40569 and CVE-2023-40589).

References


[ 1 ] Bug #2236653 - TRIAGE-CVE-2023-40569 freerdp: an out-of-bounds write in the `progressive_decompress` function due to incorrect calculations [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2236653

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-74108ca60d' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
critical
Lowest
Low
Medium
High
Critical

Name: freerdp
Product: Fedora 39
Version: 2.11.1
Release: 1.fc39
Summary: Free implementation of the Remote Desktop Protocol (RDP)

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here