FreeRDP是FreeRDP团队的一款开源的远程桌面协议(RDP)的实现。 FreeRDP 3.5.1 版本之前存在安全漏洞,该漏洞源于基于 FreeRDP 的客户端容易受到越界读取的影响。当以两倍大小读取 WCHAR 字符串并将其转换为 UTF-8 、 base64 解码时,会发生这种情况。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2024-32659 | 9.8 CRITICAL | freerdp_image_copy out of bound read |
| CVE-2024-32658 | 9.8 CRITICAL | FreeRDP ExtractRunLengthRegular* out of bound read |
| CVE-2024-32661 | 7.5 HIGH | FreeRDP rdp_write_logon_info_v1 NULL access |
| CVE-2024-32660 | 7.5 HIGH | FreeRDP zgfx_decompress out of memory vulnerability |
No comments yet