CVE-2024-32658
published 2024-04-23CVE-2024-32658: FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients prior to version 3.5.1 are vulnerable to out-of-bounds read. Version…
PriorityP351critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.37%
69.1th percentile
FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients prior to version 3.5.1 are vulnerable to out-of-bounds read. Version 3.5.1 contains a patch for the issue. No known workarounds are available.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | freerdp2 | < freerdp2 2.11.7+dfsg1-6~deb12u1 (bookworm) | freerdp2 2.11.7+dfsg1-6~deb12u1 (bookworm) |
| debian | freerdp3 | < freerdp2 2.11.7+dfsg1-6~deb12u1 (bookworm) | freerdp2 2.11.7+dfsg1-6~deb12u1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| freerdp | freerdp | < 3.5.1 | 3.5.1 |
| freerdp | freerdp | < 2.11.7 | 2.11.7 |
| freerdp | freerdp | >= 3.0.0 < 3.5.1 | 3.5.1 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
FreeRDP vulnerabilities
vendor_ubuntu·2025-03-11·CVSS 9.8
CVE-2024-32040 [CRITICAL] FreeRDP vulnerabilities
Title: FreeRDP vulnerabilities
Summary: Several security issues were fixed in FreeRDP.
Evgeny Legerov discovered that FreeRDP incorrectly handled certain memory
operations. If a user were tricked into connecting to a malicious server, a
remote attacker could use this issue to cause FreeRDP to crash, resulting
in a denial of service, or possibly execute arbitrary code.
(CVE-2024-32039, CVE-2024-32040, CVE-2024-32041)
Evgeny Legerov discovered that FreeRDP incorrectly handled certain memory
operations. If a user were tricked into connecting to a malicious server, a
remote attacker could possibly use this issue to cause FreeRDP to crash,
resulting in a denial of service. (CVE-2024-32458, CVE-2024-32460)
It was discovered that FreeRDP incorrectly handled certain memory
operations. If a use
Ubuntu
FreeRDP vulnerabilities
vendor_ubuntu·2024-04-29
CVE-2024-32658 FreeRDP vulnerabilities
Title: FreeRDP vulnerabilities
Summary: Several security issues were fixed in FreeRDP.
It was discovered that FreeRDP incorrectly handled certain memory
operations. If a user were tricked into connecting to a malicious server, a
remote attacker could possibly use this issue to cause FreeRDP to crash,
resulting in a denial of service.
Instructions: After a standard system update you need to restart your session to make all
the necessary changes.
Red Hat
FreeRDP: ExtractRunLengthRegular* out of bound read
vendor_redhat·2024-04-23·CVSS 9.8
CVE-2024-32658 [CRITICAL] CWE-125 FreeRDP: ExtractRunLengthRegular* out of bound read
FreeRDP: ExtractRunLengthRegular* out of bound read
FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients prior to version 3.5.1 are vulnerable to out-of-bounds read. Version 3.5.1 contains a patch for the issue. No known workarounds are available.
Package: freerdp (Red Hat Enterprise Linux 10) - Not affected
Package: freerdp (Red Hat Enterprise Linux 6) - Out of support scope
Package: freerdp (Red Hat Enterprise Linux 7) - Out of support scope
Package: freerdp (Red Hat Enterprise Linux 8) - Fix deferred
Debian
CVE-2024-32658: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based c...
vendor_debian·2024·CVSS 9.8
CVE-2024-32658 [CRITICAL] CVE-2024-32658: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based c...
FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients prior to version 3.5.1 are vulnerable to out-of-bounds read. Version 3.5.1 contains a patch for the issue. No known workarounds are available.
Scope: local
bookworm: resolved (fixed in 2.11.7+dfsg1-6~deb12u1)
bullseye: resolved (fixed in 2.3.0+dfsg1-2+deb11u2)
OSV
CVE-2024-32658: FreeRDP is a free implementation of the Remote Desktop Protocol
osv·2024-04-23·CVSS 9.8
CVE-2024-32658 [CRITICAL] CVE-2024-32658: FreeRDP is a free implementation of the Remote Desktop Protocol
FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients prior to version 3.5.1 are vulnerable to out-of-bounds read. Version 3.5.1 contains a patch for the issue. No known workarounds are available.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/FreeRDP/FreeRDP/commit/1a755d898ddc028cc818d0dd9d49d5acff4c44bfhttps://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-vpv3-m3m9-4c2vhttps://lists.fedoraproject.org/archives/list/[email protected]/message/5JL476WVJSIE7SBUKVJRVA6A52V2HOLZ/https://lists.fedoraproject.org/archives/list/[email protected]/message/7SIS6NUNLUBOV4CPCSWKDE6T6C2W3WTR/https://lists.fedoraproject.org/archives/list/[email protected]/message/PX3U6YPZQ7PEJBVKSBUOLWVH7DHROHY5/https://lists.fedoraproject.org/archives/list/[email protected]/message/ZKI4UISUXYNBPN4K6TIQKDRTIJ6CDCKJ/https://oss-fuzz.com/testcase-detail/4852534033317888https://oss-fuzz.com/testcase-detail/6196819496337408https://github.com/FreeRDP/FreeRDP/commit/1a755d898ddc028cc818d0dd9d49d5acff4c44bfhttps://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-vpv3-m3m9-4c2vhttps://lists.debian.org/debian-lts-announce/2025/02/msg00016.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/5JL476WVJSIE7SBUKVJRVA6A52V2HOLZ/https://lists.fedoraproject.org/archives/list/[email protected]/message/7SIS6NUNLUBOV4CPCSWKDE6T6C2W3WTR/https://lists.fedoraproject.org/archives/list/[email protected]/message/PX3U6YPZQ7PEJBVKSBUOLWVH7DHROHY5/https://lists.fedoraproject.org/archives/list/[email protected]/message/ZKI4UISUXYNBPN4K6TIQKDRTIJ6CDCKJ/https://oss-fuzz.com/testcase-detail/4852534033317888https://oss-fuzz.com/testcase-detail/6196819496337408
2024-04-23
Published