cbcvebase.

Debian Freerdp2 vulnerabilities

148 known vulnerabilities affecting debian/freerdp2.

Total CVEs
148
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL13HIGH34MEDIUM68LOW32

Vulnerabilities

Page 1 of 8
CVE-2022-24883P2HIGHCVSS 7.4fixed in freerdp2 2.7.0+dfsg1-1 (bookworm)2022
CVE-2022-24883 [HIGH] CVE-2022-24883: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol (RDP). Prior to ... FreeRDP is a free implementation of the Remote Desktop Protocol (RDP). Prior to version 2.7.0, server side authentication against a `SAM` file might be successful for invalid credentials if the server has configured an invalid `SAM` file path. FreeRDP based clients are not affected. RDP server implementations using FreeRDP to authenticate against a `SAM` file are a
debian
CVE-2024-32039P2CRITICALCVSS 9.8fixed in freerdp2 2.11.7+dfsg1-6~deb12u1 (bookworm)2024
CVE-2024-32039 [CRITICAL] CVE-2024-32039: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based c... FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients using a version of FreeRDP prior to 3.5.0 or 2.11.6 are vulnerable to integer overflow and out-of-bounds write. Versions 3.5.0 and 2.11.6 patch the issue. As a workaround, do not use `/gfx` options (e.g. deactivate with `/bpp:32` or `/rfx` as it is on by default). Scope: loca
debian
CVE-2026-31806P3CRITICALCVSS 9.3fixed in freerdp3 3.24.0+dfsg-1 (forky)2026
CVE-2026-31806 [CRITICAL] CVE-2026-31806: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0... FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, the gdi_surface_bits() function processes SURFACE_BITS_COMMAND messages sent by the RDP server. When the command is handled using NSCodec, the bmp.width and bmp.height values provided by the server are not properly validated against the actual desktop dimensions. A malicious RDP s
debian
CVE-2024-32040P3HIGHCVSS 8.1fixed in freerdp2 2.11.7+dfsg1-6~deb12u1 (bookworm)2024
CVE-2024-32040 [HIGH] CVE-2024-32040: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based c... FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients that use a version of FreeRDP prior to 3.5.0 or 2.11.6 and have connections to servers using the `NSC` codec are vulnerable to integer underflow. Versions 3.5.0 and 2.11.6 patch the issue. As a workaround, do not use the NSC codec (e.g. use `-nsc`). Scope: local bookworm: resolve
debian
CVE-2024-32458P3CRITICALCVSS 9.8fixed in freerdp2 2.11.7+dfsg1-6~deb12u1 (bookworm)2024
CVE-2024-32458 [CRITICAL] CVE-2024-32458: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based c... FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients that use a version of FreeRDP prior to 3.5.0 or 2.11.6 are vulnerable to out-of-bounds read. Versions 3.5.0 and 2.11.6 patch the issue. As a workaround, use `/gfx` or `/rfx` modes (on by default, require server side support). Scope: local bookworm: resolved (fixed in 2.11.7+d
debian
CVE-2026-23531P2HIGHCVSS 7.7fixed in freerdp3 3.21.0+dfsg-1 (forky)2026
CVE-2026-23531 [HIGH] CVE-2026-23531: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to versio... FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, in ClearCodec, when `glyphData` is present, `clear_decompress` calls `freerdp_image_copy_no_overlap` without validating the destination rectangle, allowing an out-of-bounds read/write via crafted RDPGFX surface updates. A malicious server can trigger a client‑side heap buffer
debian
CVE-2026-23530P2HIGHCVSS 7.7fixed in freerdp3 3.21.0+dfsg-1 (forky)2026
CVE-2026-23530 [HIGH] CVE-2026-23530: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to versio... FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0,`freerdp_bitmap_decompress_planar` does not validate `nSrcWidth`/`nSrcHeight` against `planar->maxWidth`/`maxHeight` before RLE decode. A malicious server can trigger a client‑side heap buffer overflow, causing a crash (DoS) and potential heap corruption with code‑execution ris
debian
CVE-2026-23532P2HIGHCVSS 7.7fixed in freerdp3 3.21.0+dfsg-1 (forky)2026
CVE-2026-23532 [HIGH] CVE-2026-23532: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to versio... FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, a client-side heap buffer overflow occurs in the FreeRDP client’s `gdi_SurfaceToSurface` path due to a mismatch between destination rectangle clamping and the actual copy size. A malicious server can trigger a client‑side heap buffer overflow, causing a crash (DoS) and potenti
debian
CVE-2026-23534P3HIGHCVSS 7.7fixed in freerdp3 3.21.0+dfsg-1 (forky)2026
CVE-2026-23534 [HIGH] CVE-2026-23534: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to versio... FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, a client-side heap buffer overflow occurs in the ClearCodec bands decode path when crafted band coordinates allow writes past the end of the destination surface buffer. A malicious server can trigger a client‑side heap buffer overflow, causing a crash (DoS) and potential heap
debian
CVE-2024-32460P3HIGHCVSS 8.1fixed in freerdp2 2.11.7+dfsg1-6~deb12u1 (bookworm)2024
CVE-2024-32460 [HIGH] CVE-2024-32460: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based b... FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based based clients using `/bpp:32` legacy `GDI` drawing path with a version of FreeRDP prior to 3.5.0 or 2.11.6 are vulnerable to out-of-bounds read. Versions 3.5.0 and 2.11.6 patch the issue. As a workaround, use modern drawing paths (e.g. `/rfx` or `/gfx` options). The workaround requires s
debian
CVE-2026-22858P3MEDIUMCVSS 5.6fixed in freerdp3 3.20.2+dfsg-1 (forky)2026
CVE-2026-22858 [MEDIUM] CVE-2026-22858: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1... FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, global-buffer-overflow was observed in FreeRDP's Base64 decoding path. The root cause appears to be implementation-defined char signedness: on Arm/AArch64 builds, plain char is treated as unsigned, so the guard c <= 0 can be optimized into a simple c != 0 check. As a result, non-ASC
debian
CVE-2018-8788P3CRITICALCVSS 9.8fixed in freerdp2 2.0.0~git20181120.1.e21b72c95+dfsg1-1 (bookworm)2018
CVE-2018-8788 [CRITICAL] CVE-2018-8788: freerdp2 - FreeRDP prior to version 2.0.0-rc4 contains an Out-Of-Bounds Write of up to 4 by... FreeRDP prior to version 2.0.0-rc4 contains an Out-Of-Bounds Write of up to 4 bytes in function nsc_rle_decode() that results in a memory corruption and possibly even a remote code execution. Scope: local bookworm: resolved (fixed in 2.0.0~git20181120.1.e21b72c95+dfsg1-1) bullseye: resolved (fixed in 2.0.0~git20181120.1.e21b72c95+dfsg1-1)
debian
CVE-2018-8785P3CRITICALCVSS 9.8fixed in freerdp2 2.0.0~git20181120.1.e21b72c95+dfsg1-1 (bookworm)2018
CVE-2018-8785 [CRITICAL] CVE-2018-8785: freerdp2 - FreeRDP prior to version 2.0.0-rc4 contains a Heap-Based Buffer Overflow in func... FreeRDP prior to version 2.0.0-rc4 contains a Heap-Based Buffer Overflow in function zgfx_decompress() that results in a memory corruption and probably even a remote code execution. Scope: local bookworm: resolved (fixed in 2.0.0~git20181120.1.e21b72c95+dfsg1-1) bullseye: resolved (fixed in 2.0.0~git20181120.1.e21b72c95+dfsg1-1)
debian
CVE-2018-8784P3CRITICALCVSS 9.8fixed in freerdp2 2.0.0~git20181120.1.e21b72c95+dfsg1-1 (bookworm)2018
CVE-2018-8784 [CRITICAL] CVE-2018-8784: freerdp2 - FreeRDP prior to version 2.0.0-rc4 contains a Heap-Based Buffer Overflow in func... FreeRDP prior to version 2.0.0-rc4 contains a Heap-Based Buffer Overflow in function zgfx_decompress_segment() that results in a memory corruption and probably even a remote code execution. Scope: local bookworm: resolved (fixed in 2.0.0~git20181120.1.e21b72c95+dfsg1-1) bullseye: resolved (fixed in 2.0.0~git20181120.1.e21b72c95+dfsg1-1)
debian
CVE-2026-23883P2HIGHCVSS 7.7fixed in freerdp3 3.21.0+dfsg-1 (forky)2026
CVE-2026-23883 [HIGH] CVE-2026-23883: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to versio... FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, `xf_Pointer_New` frees `cursorPixels` on failure, then `pointer_free` calls `xf_Pointer_Free` and frees it again, triggering ASan UAF. A malicious server can trigger a client‑side use after free, causing a crash (DoS) and potential heap corruption with code‑execution risk depe
debian
CVE-2023-40186P3MEDIUMCVSS 6.5fixed in freerdp2 2.11.7+dfsg1-6~deb12u1 (bookworm)2023
CVE-2023-40186 [MEDIUM] CVE-2023-40186: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released ... FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versions are subject to an IntegerOverflow leading to Out-Of-Bound Write Vulnerability in the `gdi_CreateSurface` function. This issue affects FreeRDP based clients only. FreeRDP proxies are not affected as image decoding is not done by a proxy. This
debian
CVE-2024-32459P3CRITICALCVSS 9.8fixed in freerdp2 2.11.7+dfsg1-6~deb12u1 (bookworm)2024
CVE-2024-32459 [CRITICAL] CVE-2024-32459: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based c... FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients and servers that use a version of FreeRDP prior to 3.5.0 or 2.11.6 are vulnerable to out-of-bounds read. Versions 3.5.0 and 2.11.6 patch the issue. No known workarounds are available. Scope: local bookworm: resolved (fixed in 2.11.7+dfsg1-6~deb12u1) bullseye: resolved (fixed
debian
CVE-2018-8787P3CRITICALCVSS 9.8fixed in freerdp2 2.0.0~git20181120.1.e21b72c95+dfsg1-1 (bookworm)2018
CVE-2018-8787 [CRITICAL] CVE-2018-8787: freerdp2 - FreeRDP prior to version 2.0.0-rc4 contains an Integer Overflow that leads to a ... FreeRDP prior to version 2.0.0-rc4 contains an Integer Overflow that leads to a Heap-Based Buffer Overflow in function gdi_Bitmap_Decompress() and results in a memory corruption and probably even a remote code execution. Scope: local bookworm: resolved (fixed in 2.0.0~git20181120.1.e21b72c95+dfsg1-1) bullseye: resolved (fixed in 2.0.0~git20181120.1.e21b72c95+dfsg
debian
CVE-2018-8786P3CRITICALCVSS 9.8fixed in freerdp2 2.0.0~git20181120.1.e21b72c95+dfsg1-1 (bookworm)2018
CVE-2018-8786 [CRITICAL] CVE-2018-8786: freerdp2 - FreeRDP prior to version 2.0.0-rc4 contains an Integer Truncation that leads to ... FreeRDP prior to version 2.0.0-rc4 contains an Integer Truncation that leads to a Heap-Based Buffer Overflow in function update_read_bitmap_update() and results in a memory corruption and probably even a remote code execution. Scope: local bookworm: resolved (fixed in 2.0.0~git20181120.1.e21b72c95+dfsg1-1) bullseye: resolved (fixed in 2.0.0~git20181120.1.e21b72c9
debian
CVE-2026-22852P3MEDIUMCVSS 6.8fixed in freerdp3 3.20.2+dfsg-1 (forky)2026
CVE-2026-22852 [MEDIUM] CVE-2026-22852: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1... FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a malicious RDP server can trigger a heap-buffer-overflow write in the FreeRDP client when processing Audio Input (AUDIN) format lists. audin_process_formats reuses callback->formats_count across multiple MSG_SNDIN_FORMATS PDUs and writes past the newly allocated formats array, caus
debian
Debian Freerdp2 vulnerabilities | cvebase