Bug 1198919 - (CVE-2022-24882) VUL-0: CVE-2022-24882: freerdp: NTLM does not properly check parameters
(CVE-2022-24882)
VUL-0: CVE-2022-24882: freerdp: NTLM does not properly check parameters
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P2 - High : Critical
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/330131/
CVSSv3.1:SUSE:CVE-2022-24882:9.8:(AV:...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2022-04-27 08:37 UTC by Hu
Modified: 2022-12-20 11:26 UTC (History)
5 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Hu 2022-04-27 08:37:15 UTC
CVE-2022-24882

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP). In
versions prior to 2.7.0, NT LAN Manager (NTLM) authentication does not properly
abort when someone provides and empty password value. This issue affects FreeRDP
based RDP Server implementations. RDP clients are not affected. The
vulnerability is patched in FreeRDP 2.7.0. There are currently no known
workarounds.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-24882
https://github.com/FreeRDP/FreeRDP/releases/tag/2.7.0
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-24882
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-6x5p-gp49-3jhh
https://github.com/FreeRDP/FreeRDP/pull/7750
https://gitlab.gnome.org/GNOME/gnome-remote-desktop/-/issues/95
Comment 1 Hu 2022-04-27 08:37:43 UTC
Affected:
 - SUSE:SLE-12-SP2:Update/freerdp          2.1.2
 - SUSE:SLE-15-SP2:Update/freerdp          2.1.2
 - SUSE:SLE-15-SP4:Update/freerdp          2.4.0
 - openSUSE:Backports:SLE-15-SP3/freerdp   2.1.2
 - openSUSE:Factory/freerdp                2.6.1
Comment 3 Hu 2022-05-13 07:26:40 UTC
Hi, is there any progress on this?
If you need help with anything, please let me know.
Comment 5 Swamp Workflow Management 2022-07-11 13:17:49 UTC
SUSE-SU-2022:2352-1: An update that fixes two vulnerabilities is now available.

Category: security (critical)
Bug References: 1198919,1198921
CVE References: CVE-2022-24882,CVE-2022-24883
JIRA References: 
Sources used:
SUSE Linux Enterprise Workstation Extension 12-SP5 (src):    freerdp-2.1.2-12.23.1
SUSE Linux Enterprise Software Development Kit 12-SP5 (src):    freerdp-2.1.2-12.23.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 6 Swamp Workflow Management 2022-07-11 16:16:49 UTC
SUSE-SU-2022:2354-1: An update that fixes two vulnerabilities is now available.

Category: security (critical)
Bug References: 1198919,1198921
CVE References: CVE-2022-24882,CVE-2022-24883
JIRA References: 
Sources used:
openSUSE Leap 15.4 (src):    freerdp-2.4.0-150400.3.3.1
SUSE Linux Enterprise Workstation Extension 15-SP4 (src):    freerdp-2.4.0-150400.3.3.1
SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP4 (src):    freerdp-2.4.0-150400.3.3.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 7 Swamp Workflow Management 2022-07-11 16:17:29 UTC
SUSE-SU-2022:2353-1: An update that fixes two vulnerabilities is now available.

Category: security (critical)
Bug References: 1198919,1198921
CVE References: CVE-2022-24882,CVE-2022-24883
JIRA References: 
Sources used:
openSUSE Leap 15.3 (src):    freerdp-2.1.2-150200.15.15.1
SUSE Linux Enterprise Workstation Extension 15-SP3 (src):    freerdp-2.1.2-150200.15.15.1
SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP3 (src):    freerdp-2.1.2-150200.15.15.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 8 Jia Zhaocong 2022-10-19 08:34:23 UTC
Cleaning up GNOME CVE backlog. The fix has been submitted and accepted. Assign back to security team.
Comment 9 Hu 2022-12-20 11:26:07 UTC
done