CVE-2023-39355
published 2023-08-31CVE-2023-39355: FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Versions of FreeRDP on the 3.x release branch before…
PriorityP350critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.07%
61.1th percentile
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Versions of FreeRDP on the 3.x release branch before beta3 are subject to a Use-After-Free in processing `RDPGFX_CMDID_RESETGRAPHICS` packets. If `context->maxPlaneSize` is 0, `context->planesBuffer` will be freed. However, without updating `context->planesBuffer`, this leads to a Use-After-Free exploit vector. In most environments this should only result in a crash. This issue has been addressed in version 3.0.0-beta3 and users of the beta 3.x releases are advised to upgrade. There are no known workarounds for this vulnerability.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | freerdp2 | — | — |
| freerdp | freerdp | — | — |
| freerdp | freerdp | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian7.0LOW
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
freerdp: use-after-free in RDPGFX_CMDID_RESETGRAPHICS
vendor_redhat·2023-08-31·CVSS 7.0
CVE-2023-39355 [HIGH] CWE-416 freerdp: use-after-free in RDPGFX_CMDID_RESETGRAPHICS
freerdp: use-after-free in RDPGFX_CMDID_RESETGRAPHICS
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Versions of FreeRDP on the 3.x release branch before beta3 are subject to a Use-After-Free in processing `RDPGFX_CMDID_RESETGRAPHICS` packets. If `context->maxPlaneSize` is 0, `context->planesBuffer` will be freed. However, without updating `context->planesBuffer`, this leads to a Use-After-Free exploit vector. In most environments this should only result in a crash. This issue has been addressed in version 3.0.0-beta3 and users of the beta 3.x releases are advised to upgrade. There are no known workarounds for this vulnerability.
A flaw was found in FreeRDP. If `context->maxPlaneSize` is 0, `context->planesBuffer` will be freed.
Debian
CVE-2023-39355: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released ...
vendor_debian·2023·CVSS 7.0
CVE-2023-39355 [HIGH] CVE-2023-39355: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released ...
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Versions of FreeRDP on the 3.x release branch before beta3 are subject to a Use-After-Free in processing `RDPGFX_CMDID_RESETGRAPHICS` packets. If `context->maxPlaneSize` is 0, `context->planesBuffer` will be freed. However, without updating `context->planesBuffer`, this leads to a Use-After-Free exploit vector. In most environments this should only result in a crash. This issue has been addressed in version 3.0.0-beta3 and users of the beta 3.x releases are advised to upgrade. There are no known workarounds for this vulnerability.
Scope: local
bookworm: resolved
bullseye: resolved
OSV
CVE-2023-39355: FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license
osv·2023-08-31·CVSS 9.8
CVE-2023-39355 [CRITICAL] CVE-2023-39355: FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Versions of FreeRDP on the 3.x release branch before beta3 are subject to a Use-After-Free in processing `RDPGFX_CMDID_RESETGRAPHICS` packets. If `context->maxPlaneSize` is 0, `context->planesBuffer` will be freed. However, without updating `context->planesBuffer`, this leads to a Use-After-Free exploit vector. In most environments this should only result in a crash. This issue has been addressed in version 3.0.0-beta3 and users of the beta 3.x releases are advised to upgrade. There are no known workarounds for this vulnerability.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/FreeRDP/FreeRDP/commit/d6f9d33a7db0b346195b6a15b5b99944ba41beeehttps://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-hvwj-vmg6-2f5hhttps://lists.debian.org/debian-lts-announce/2023/10/msg00008.htmlhttps://security.gentoo.org/glsa/202401-16https://github.com/FreeRDP/FreeRDP/commit/d6f9d33a7db0b346195b6a15b5b99944ba41beeehttps://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-hvwj-vmg6-2f5hhttps://lists.debian.org/debian-lts-announce/2023/10/msg00008.htmlhttps://security.gentoo.org/glsa/202401-16
2023-08-31
Published