Vulnerability CVE-2022-39283: Information
Description
FreeRDP is a free remote desktop protocol library and clients. All FreeRDP based clients when using the `/video` command line switch might read uninitialized data, decode it as audio/video and display the result. FreeRDP based server implementations are not affected. This issue has been patched in version 2.8.1. If you cannot upgrade do not use the `/video` switch.
Severity: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Fixed packages
Package name | Branch | Fixed in version | Version from repository | Errata ID | Task # | State |
---|---|---|---|---|---|---|
freerdp | sisyphus | 2.8.1-alt1 | 2.11.7-alt2 | ALT-PU-2022-2857-1 | 308358 | Fixed |
freerdp | sisyphus_e2k | 2.8.1-alt1.1 | 2.11.7-alt2 | ALT-PU-2022-6969-1 | - | Fixed |
freerdp | sisyphus_riscv64 | 2.8.1-alt1 | 2.11.7-alt2 | ALT-PU-2022-6612-1 | - | Fixed |
freerdp | p10 | 2.8.1-alt1 | 2.11.7-alt2 | ALT-PU-2022-2872-1 | 308539 | Fixed |
freerdp | p10_e2k | 2.8.1-alt1.1 | 2.11.7-alt2 | ALT-PU-2022-6929-1 | - | Fixed |
freerdp | p9 | 2.9.0-alt1 | 2.9.0-alt1 | ALT-PU-2022-3288-1 | 310221 | Fixed |
freerdp | c10f1 | 2.8.1-alt1 | 2.11.6-alt1 | ALT-PU-2022-2872-1 | 308539 | Fixed |
freerdp | c9f2 | 2.8.1-alt1 | 2.11.6-alt1 | ALT-PU-2022-2881-1 | 308589 | Fixed |
freerdp | p11 | 2.8.1-alt1 | 2.11.7-alt2 | ALT-PU-2022-2857-1 | 308358 | Fixed |
References to Advisories, Solutions, and Tools
Hyperlink | Resource |
---|---|
https://github.com/FreeRDP/FreeRDP/releases/tag/2.8.1 |
|
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-6cf9-3328-qrvh |
|
GLSA-202210-24 |
|
FEDORA-2022-d6310a1308 | |
FEDORA-2022-e733724edb | |
FEDORA-2022-fd6e43dec8 | |
[debian-lts-announce] 20231117 [SECURITY] [DLA 3654-1] freerdp2 security update |