cbcvebase.
CVE-2022-39316
published 2022-11-16

CVE-2022-39316: FreeRDP is a free remote desktop protocol library and clients. In affected versions there is an out of bound read in ZGFX decoder component of FreeRDP. A…

PriorityP428medium5.7CVSS 3.1
AVNACLPRLUIRSUCNINAH
EPSS
0.97%
57.8th percentile
FreeRDP is a free remote desktop protocol library and clients. In affected versions there is an out of bound read in ZGFX decoder component of FreeRDP. A malicious server can trick a FreeRDP based client to read out of bound data and try to decode it likely resulting in a crash. This issue has been addressed in the 2.9.0 release. Users are advised to upgrade.

Affected

4 ranges
VendorProductVersion rangeFixed in
debianfreerdp2< freerdp2 2.9.0+dfsg1-1 (bookworm)freerdp2 2.9.0+dfsg1-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
freerdpfreerdp< 2.9.02.9.0

CVSS provenance

nvdv3.15.7MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian4.8MEDIUM
vendor_redhat4.8MEDIUM
vendor_ubuntu3.5LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.