Bugzilla – Bug 1205564
VUL-0: CVE-2022-39319: freerdp: malicious server can trick a FreeRDP based client to read out of bound data and send it back to the server
Last modified: 2022-11-29 20:30:23 UTC
CVE-2022-39319 FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing input length validation in the `urbdrc` channel. A malicious server can trick a FreeRDP based client to read out of bound data and send it back to the server. This issue has been addressed in version 2.9.0 and all users are advised to upgrade. Users unable to upgrade should not use the `/usb` redirection switch. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-39319 http://www.cvedetails.com/cve/CVE-2022-39319/ https://www.cve.org/CVERecord?id=CVE-2022-39319 https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-mvxm-wfj2-5fvh https://github.com/FreeRDP/FreeRDP/commit/11555828d2cf289b350baba5ad1f462f10b80b76
SUSE-SU-2022:4224-1: An update that fixes two vulnerabilities is now available. Category: security (moderate) Bug References: 1205563,1205564 CVE References: CVE-2022-39318,CVE-2022-39319 JIRA References: Sources used: openSUSE Leap 15.4 (src): freerdp-2.4.0-150400.3.12.1 SUSE Linux Enterprise Workstation Extension 15-SP4 (src): freerdp-2.4.0-150400.3.12.1 SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP4 (src): freerdp-2.4.0-150400.3.12.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2022:4293-1: An update that fixes two vulnerabilities is now available. Category: security (moderate) Bug References: 1205563,1205564 CVE References: CVE-2022-39318,CVE-2022-39319 JIRA References: Sources used: SUSE Linux Enterprise Workstation Extension 12-SP5 (src): freerdp-2.1.2-12.32.1 SUSE Linux Enterprise Software Development Kit 12-SP5 (src): freerdp-2.1.2-12.32.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2022:4292-1: An update that fixes two vulnerabilities is now available. Category: security (moderate) Bug References: 1205563,1205564 CVE References: CVE-2022-39318,CVE-2022-39319 JIRA References: Sources used: openSUSE Leap 15.3 (src): freerdp-2.1.2-150200.15.24.1 SUSE Linux Enterprise Workstation Extension 15-SP3 (src): freerdp-2.1.2-150200.15.24.1 SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP3 (src): freerdp-2.1.2-150200.15.24.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.