Vulnerability CVE-2021-41160: Information

Description

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. In affected versions a malicious server might trigger out of bound writes in a connected client. Connections using GDI or SurfaceCommands to send graphics updates to the client might send `0` width/height or out of bound rectangles to trigger out of bound writes. With `0` width or heigth the memory allocation will be `0` but the missing bounds checks allow writing to the pointer at this (not allocated) region. This issue has been patched in FreeRDP 2.4.1.

Severity: HIGH (8.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Published: Oct. 21, 2021
Modified: Nov. 17, 2023
Error type identifier: CWE-787

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
freerdpsisyphus2.4.1-alt12.11.7-alt2ALT-PU-2021-3098-1287769Fixed
freerdpp102.4.1-alt12.11.6-alt1ALT-PU-2021-3106-1287814Fixed
freerdpp92.4.1-alt12.9.0-alt1ALT-PU-2021-3177-1287815Fixed
freerdpc10f12.4.1-alt12.11.6-alt1ALT-PU-2021-3106-1287814Fixed
freerdpc9f22.4.1-alt12.11.6-alt1ALT-PU-2021-3105-1287816Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:*
      End excliding
      2.4.1

      Configuration 2

      cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*

      cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*

      cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*