The vendor explicitly identifies these products as affected by this CVE.
- freerdp as a component of Red Hat Enterprise Linux 10
- freerdp-devel as a component of Red Hat Enterprise Linux 10
- freerdp-libs as a component of Red Hat Enterprise Linux 10
- freerdp-server as a component of Red Hat Enterprise Linux 10
- freerdp.src as a component of Red Hat Enterprise Linux 10
- libwinpr as a component of Red Hat Enterprise Linux 10
- libwinpr-devel as a component of Red Hat Enterprise Linux 10
- freerdp as a component of Red Hat Enterprise Linux 6
- freerdp-devel as a component of Red Hat Enterprise Linux 6
- freerdp-libs as a component of Red Hat Enterprise Linux 6
- freerdp-plugins as a component of Red Hat Enterprise Linux 6
- freerdp.src as a component of Red Hat Enterprise Linux 6
- Summary
- A flaw was found in FreeRDP. FreeRDP clients that negotiate RDPGFX AVC444 with an H.264 decoder backend are vulnerable to a heap-buffer-overflow. A malicious Remote Desktop Protocol (RDP) server can supply crafted surface dimensions, causing an undersized buffer to be allocated. This can lead to a client crash and potentially allow for arbitrary code execution through attacker-influenced heap corruption.
- Remediation
- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
