CVE-2021-41160
published 2021-10-21CVE-2021-41160: FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. In affected versions a malicious server might trigger…
PriorityP348high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
1.55%
72.4th percentile
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. In affected versions a malicious server might trigger out of bound writes in a connected client. Connections using GDI or SurfaceCommands to send graphics updates to the client might send `0` width/height or out of bound rectangles to trigger out of bound writes. With `0` width or heigth the memory allocation will be `0` but the missing bounds checks allow writing to the pointer at this (not allocated) region. This issue has been patched in FreeRDP 2.4.1.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | freerdp2 | < freerdp2 2.4.1+dfsg1-1 (bookworm) | freerdp2 2.4.1+dfsg1-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| freerdp | freerdp | < 2.4.1 | 2.4.1 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_ubuntu5.8MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
FreeRDP vulnerabilities
vendor_ubuntu·2021-11-23·CVSS 5.8
CVE-2021-41159 [MEDIUM] FreeRDP vulnerabilities
Title: FreeRDP vulnerabilities
Summary: Several security issues were fixed in FreeRDP.
It was discovered that FreeRDP incorrectly handled certain inputs.
An attacker could possibly use this issue to execute arbitrary code
or cause a crash. (CVE-2021-41159)
It was discovered that FreeRDP incorrectly handled certain connections.
An attacker could possibly use this issue to execute arbitrary code or
cause a crash. (CVE-2021-41160)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
freerdp: improper region checks in all clients allow out of bound write to memory
vendor_redhat·2021-10-21·CVSS 5.3
CVE-2021-41160 [MEDIUM] CWE-787 freerdp: improper region checks in all clients allow out of bound write to memory
freerdp: improper region checks in all clients allow out of bound write to memory
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. In affected versions a malicious server might trigger out of bound writes in a connected client. Connections using GDI or SurfaceCommands to send graphics updates to the client might send `0` width/height or out of bound rectangles to trigger out of bound writes. With `0` width or heigth the memory allocation will be `0` but the missing bounds checks allow writing to the pointer at this (not allocated) region. This issue has been patched in FreeRDP 2.4.1.
A flaw was found in the FreeRDP client where it fails to validate input data when using connections with GDI or SurfaceCommands. This flaw could allow
Debian
CVE-2021-41160: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released ...
vendor_debian·2021·CVSS 5.3
CVE-2021-41160 [MEDIUM] CVE-2021-41160: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released ...
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. In affected versions a malicious server might trigger out of bound writes in a connected client. Connections using GDI or SurfaceCommands to send graphics updates to the client might send `0` width/height or out of bound rectangles to trigger out of bound writes. With `0` width or heigth the memory allocation will be `0` but the missing bounds checks allow writing to the pointer at this (not allocated) region. This issue has been patched in FreeRDP 2.4.1.
Scope: local
bookworm: resolved (fixed in 2.4.1+dfsg1-1)
bullseye: resolved (fixed in 2.3.0+dfsg1-2+deb11u2)
OSV
freerdp2 vulnerabilities
osv·2021-11-23·CVSS 8.8
CVE-2021-41159 [HIGH] freerdp2 vulnerabilities
freerdp2 vulnerabilities
It was discovered that FreeRDP incorrectly handled certain inputs.
An attacker could possibly use this issue to execute arbitrary code
or cause a crash. (CVE-2021-41159)
It was discovered that FreeRDP incorrectly handled certain connections.
An attacker could possibly use this issue to execute arbitrary code or
cause a crash. (CVE-2021-41160)
OSV
CVE-2021-41160: FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license
osv·2021-10-21·CVSS 8.8
CVE-2021-41160 [HIGH] CVE-2021-41160: FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. In affected versions a malicious server might trigger out of bound writes in a connected client. Connections using GDI or SurfaceCommands to send graphics updates to the client might send `0` width/height or out of bound rectangles to trigger out of bound writes. With `0` width or heigth the memory allocation will be `0` but the missing bounds checks allow writing to the pointer at this (not allocated) region. This issue has been patched in FreeRDP 2.4.1.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-7c9r-6r2q-93qghttps://lists.debian.org/debian-lts-announce/2023/11/msg00010.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DWJXQOWKNR7O5HM2HFJOM4GBUFPTE3RG/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WIZUPVRGCWUDAPDOQVUGUIYUO7UWKMXX/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZXCR73EDVPLI6TRWRAWJCJ7OBYDKBB74/https://security.gentoo.org/glsa/202210-24https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-7c9r-6r2q-93qghttps://lists.debian.org/debian-lts-announce/2023/11/msg00010.htmlhttps://lists.debian.org/debian-lts-announce/2025/02/msg00016.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DWJXQOWKNR7O5HM2HFJOM4GBUFPTE3RG/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WIZUPVRGCWUDAPDOQVUGUIYUO7UWKMXX/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZXCR73EDVPLI6TRWRAWJCJ7OBYDKBB74/https://security.gentoo.org/glsa/202210-24
2021-10-21
Published