The vendor explicitly identifies these products as affected by this CVE.
- freerdp as a component of Red Hat Enterprise Linux 10
- freerdp-devel as a component of Red Hat Enterprise Linux 10
- freerdp-libs as a component of Red Hat Enterprise Linux 10
- freerdp-server as a component of Red Hat Enterprise Linux 10
- freerdp.src as a component of Red Hat Enterprise Linux 10
- libwinpr as a component of Red Hat Enterprise Linux 10
- libwinpr-devel as a component of Red Hat Enterprise Linux 10
- freerdp as a component of Red Hat Enterprise Linux 6
- freerdp-devel as a component of Red Hat Enterprise Linux 6
- freerdp-libs as a component of Red Hat Enterprise Linux 6
- freerdp-plugins as a component of Red Hat Enterprise Linux 6
- freerdp.src as a component of Red Hat Enterprise Linux 6
- Summary
- A flaw was found in FreeRDP, a remote desktop protocol client. A malicious or compromised RDP server can exploit this vulnerability by sending a specially crafted `StartStreamsRequest` with a zero value for `FrameRateDenominator`. If camera redirection is enabled on the client, this action triggers a divide-by-zero error, causing the FreeRDP client process to terminate and resulting in a denial of service for the user.
- Remediation
- To mitigate this issue, disable camera redirection when connecting to untrusted RDP servers. This can be achieved by using the --disable-camera option with the xfreerdp client or by configuring FreeRDP to not enable camera redirection. Disabling this feature will prevent the use of camera redirection functionality.
