漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Out-of-bounds Read in FreeRDP
Vulnerability Description
In FreeRDP after 1.1 and before 2.0.0, there is an out-of-bounds read in autodetect_recv_bandwidth_measure_results. A malicious server can extract up to 8 bytes of client memory with a manipulated message by providing a short input and reading the measurement result data. This has been patched in 2.0.0.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:L
Vulnerability Type
跨界内存读
Vulnerability Title
FreeRDP 缓冲区错误漏洞
Vulnerability Description
FreeRDP是FreeRDP团队的一款开源的远程桌面协议(RDP)的实现。 FreeRDP 1.1之后版本(2.0.0版本已修复)中的autodetect_recv_bandwidth_measure_results存在缓冲区错误漏洞。攻击者可通过提供简短的输入并读取测量结果数据利用该漏洞获取客户端内存。
CVSS Information
N/A
Vulnerability Type
N/A