FreeRDP integer Overflow leading to Heap Overflow
CVE-2024-22211

3.7LOW

Key Information:

Vendor

Freerdp

Status
Vendor
CVE Published:
19 January 2024

What is CVE-2024-22211?

The FreeRDP library, a widely-used open-source remote desktop protocol framework, is affected by a vulnerability due to an integer overflow in the freerdp_bitmap_planar_context_reset function. This flaw can lead to a heap-buffer overflow, which may allow a malicious server to manipulate memory handling in FreeRDP-based clients. Although the vulnerability does not facilitate data extraction over the network, the impact is significant as it can result in out-of-bounds read or write operations when improperly allocated buffers are used for displaying images. The issue has been resolved in versions 2.11.5 and 3.2.0, and users are recommended to upgrade promptly as there are currently no known workarounds.

Affected Version(s)

FreeRDP < 2.11.5 < 2.11.5

FreeRDP >= 3.0.0, < 3.2.0 < 3.0.0, 3.2.0

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.