Vulnerability CVE-2024-32459: Information

Description

FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients and servers that use a version of FreeRDP prior to 3.5.0 or 2.11.6 are vulnerable to out-of-bounds read. Versions 3.5.0 and 2.11.6 patch the issue. No known workarounds are available.

Published: April 23, 2024
Modified: April 23, 2024

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
freerdpsisyphus2.11.6-alt12.11.7-alt1.1ALT-PU-2024-6814-1345418Fixed
freerdpsisyphus_e2k2.11.7-alt1.12.11.7-alt1.1ALT-PU-2024-7151-1-Fixed
freerdpsisyphus_riscv642.11.6-alt12.11.7-alt1.1ALT-PU-2024-6834-1-Fixed
freerdpsisyphus_loongarch642.11.6-alt12.11.7-alt1.1ALT-PU-2024-6841-1-Fixed
freerdpp102.11.6-alt12.11.6-alt1ALT-PU-2024-6851-2345435Fixed
freerdpp10_e2k2.11.6-alt12.11.6-alt1ALT-PU-2024-7154-1-Fixed
freerdpc10f12.11.6-alt12.11.6-alt1ALT-PU-2024-6898-2345436Fixed
freerdpc9f22.11.6-alt12.11.6-alt1ALT-PU-2024-6847-2345438Fixed
freerdp3sisyphus3.5.0-alt13.5.1-alt1ALT-PU-2024-6812-1345417Fixed
freerdp3sisyphus_riscv643.5.0-alt13.5.1-alt1ALT-PU-2024-6832-1-Fixed
freerdp3sisyphus_loongarch643.5.0-alt13.5.1-alt1ALT-PU-2024-6840-1-Fixed
freerdp3p103.5.0-alt13.5.0-alt1ALT-PU-2024-6812-1345417Fixed

References to Advisories, Solutions, and Tools