Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Mageia: MGASA-2022-0474 Moderate: FreeRDP Input Validation Flaw

mageia
Calendar Grey December 17, 2022
Dist Mageia Esm H88
Mozilla Firefox security update for Debian resolves buffer overflow problem enabling potential data breach. Released January 15, 2023.
Affected versions of FreeRDP are missing input length validation in 'drive' channel

Summary

Affected versions of FreeRDP are missing input length validation in 'drive' channel. A malicious server can trick a FreeRDP based client to read out of bound data and send it back to the server. (CVE-2022-41877)

References

- https://bugs.mageia.org/show_bug.cgi?id=31290

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/YGQN3OWQNHSMWKOF4D35PF5ASKNLC74B/

- https://www.cve.org/CVERecord?id=CVE-2022-41877

Resolution

SRPMS

- 8/core/freerdp-2.2.0-1.5.mga8

Publication date: 17 Dec 2022
URL: https://advisories.mageia.org/MGASA-2022-0474.html
Type: security
CVE: CVE-2022-41877

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here