Out-Of-Bounds Read in FreeRDP
CVE-2023-40576
5.3MEDIUM
What is CVE-2023-40576?
The FreeRDP remote desktop client is vulnerable to an Out-Of-Bounds Read in the RleDecompress
function due to inadequate length verification of the pbSrcBuffer
variable. This flaw may result in unexpected errors or crashes when insufficient data is present. Users are strongly urged to upgrade to version 3.0.0-beta3, as previous versions are susceptible to this issue. There are no known workarounds available.
Affected Version(s)
FreeRDP >= 3.0.0-beta1, < 3.0.0-beta3