CVE-2024-32658
Published: 23 April 2024
FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients prior to version 3.5.1 are vulnerable to out-of-bounds read. Version 3.5.1 contains a patch for the issue. No known workarounds are available.
Notes
Author | Note |
---|---|
Priority reason: FreeRDP developers have rated this as being a low severity issue |
Priority
Status
Package | Release | Status |
---|---|---|
freerdp Launchpad, Ubuntu, Debian |
bionic |
Needs triage
|
focal |
Does not exist
|
|
jammy |
Does not exist
|
|
mantic |
Does not exist
|
|
noble |
Does not exist
|
|
upstream |
Needs triage
|
|
xenial |
Needs triage
|
|
freerdp2 Launchpad, Ubuntu, Debian |
bionic |
Needs triage
|
focal |
Released
(2.6.1+dfsg1-0ubuntu0.20.04.2)
|
|
jammy |
Released
(2.6.1+dfsg1-3ubuntu2.7)
|
|
mantic |
Released
(2.10.0+dfsg1-1.1ubuntu1.3)
|
|
noble |
Needs triage
|
|
upstream |
Released
(2.11.7)
|
|
Patches: upstream: https://github.com/FreeRDP/FreeRDP/commit/2b9f30a2fa4b13559a367f7cbe158e1bafe0f482 |
||
freerdp3 Launchpad, Ubuntu, Debian |
focal |
Does not exist
|
jammy |
Does not exist
|
|
mantic |
Does not exist
|
|
noble |
Released
(3.5.1+dfsg1-0ubuntu1)
|
|
upstream |
Released
(3.5.1)
|
|
Patches: upstream: https://github.com/FreeRDP/FreeRDP/commit/1a755d898ddc028cc818d0dd9d49d5acff4c44bf |
References
- https://www.cve.org/CVERecord?id=CVE-2024-32658
- https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-vpv3-m3m9-4c2v
- https://oss-fuzz.com/testcase-detail/4852534033317888
- https://oss-fuzz.com/testcase-detail/6196819496337408
- https://ubuntu.com/security/notices/USN-6752-1
- https://ubuntu.com/security/notices/USN-6759-1
- NVD
- Launchpad
- Debian