Debian Freerdp2 vulnerabilities
148 known vulnerabilities affecting debian/freerdp2.
Total CVEs
148
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL13HIGH34MEDIUM68LOW32
Vulnerabilities
Page 6 of 8
CVE-2020-11039P4HIGHCVSS 8.0fixed in freerdp2 2.1.1+dfsg1-1 (bookworm)2020
CVE-2020-11039 [HIGH] CVE-2020-11039: freerdp2 - In FreeRDP less than or equal to 2.0.0, when using a manipulated server with USB...
In FreeRDP less than or equal to 2.0.0, when using a manipulated server with USB redirection enabled (nearly) arbitrary memory can be read and written due to integer overflows in length checks. This has been patched in 2.1.0.
Scope: local
bookworm: resolved (fixed in 2.1.1+dfsg1-1)
bullseye: resolved (fixed in 2.1.1+dfsg1-1)
debian
CVE-2020-11017P4MEDIUMCVSS 6.5fixed in freerdp2 2.1.1+dfsg1-1 (bookworm)2020
CVE-2020-11017 [MEDIUM] CVE-2020-11017: freerdp2 - In FreeRDP less than or equal to 2.0.0, by providing manipulated input a malicio...
In FreeRDP less than or equal to 2.0.0, by providing manipulated input a malicious client can create a double free condition and crash the server. This is fixed in version 2.1.0.
Scope: local
bookworm: resolved (fixed in 2.1.1+dfsg1-1)
bullseye: resolved (fixed in 2.1.1+dfsg1-1)
debian
CVE-2020-4030P4LOWCVSS 3.5fixed in freerdp2 2.1.2+dfsg1-1 (bookworm)2020
CVE-2020-4030 [LOW] CVE-2020-4030: freerdp2 - In FreeRDP before version 2.1.2, there is an out of bounds read in TrioParse. Lo...
In FreeRDP before version 2.1.2, there is an out of bounds read in TrioParse. Logging might bypass string length checks due to an integer overflow. This is fixed in version 2.1.2.
Scope: local
bookworm: resolved (fixed in 2.1.2+dfsg1-1)
bullseye: resolved (fixed in 2.1.2+dfsg1-1)
debian
CVE-2020-11523P4MEDIUMCVSS 6.6fixed in freerdp2 2.1.1+dfsg1-1 (bookworm)2020
CVE-2020-11523 [MEDIUM] CVE-2020-11523: freerdp2 - libfreerdp/gdi/region.c in FreeRDP versions > 1.0 through 2.0.0-rc4 has an Integ...
libfreerdp/gdi/region.c in FreeRDP versions > 1.0 through 2.0.0-rc4 has an Integer Overflow.
Scope: local
bookworm: resolved (fixed in 2.1.1+dfsg1-1)
bullseye: resolved (fixed in 2.1.1+dfsg1-1)
debian
CVE-2020-11018P4MEDIUMCVSS 6.5fixed in freerdp2 2.1.1+dfsg1-1 (bookworm)2020
CVE-2020-11018 [MEDIUM] CVE-2020-11018: freerdp2 - In FreeRDP less than or equal to 2.0.0, a possible resource exhaustion vulnerabi...
In FreeRDP less than or equal to 2.0.0, a possible resource exhaustion vulnerability can be performed. Malicious clients could trigger out of bound reads causing memory allocation with random size. This has been fixed in 2.1.0.
Scope: local
bookworm: resolved (fixed in 2.1.1+dfsg1-1)
bullseye: resolved (fixed in 2.1.1+dfsg1-1)
debian
CVE-2020-11099P4LOWCVSS 3.5fixed in freerdp2 2.1.2+dfsg1-1 (bookworm)2020
CVE-2020-11099 [LOW] CVE-2020-11099: freerdp2 - In FreeRDP before version 2.1.2, there is an out of bounds read in license_read_...
In FreeRDP before version 2.1.2, there is an out of bounds read in license_read_new_or_upgrade_license_packet. A manipulated license packet can lead to out of bound reads to an internal buffer. This is fixed in version 2.1.2.
Scope: local
bookworm: resolved (fixed in 2.1.2+dfsg1-1)
bullseye: resolved (fixed in 2.1.2+dfsg1-1)
debian
CVE-2020-11098P4LOWCVSS 3.5fixed in freerdp2 2.1.2+dfsg1-1 (bookworm)2020
CVE-2020-11098 [LOW] CVE-2020-11098: freerdp2 - In FreeRDP before version 2.1.2, there is an out-of-bound read in glyph_cache_pu...
In FreeRDP before version 2.1.2, there is an out-of-bound read in glyph_cache_put. This affects all FreeRDP clients with `+glyph-cache` option enabled This is fixed in version 2.1.2.
Scope: local
bookworm: resolved (fixed in 2.1.2+dfsg1-1)
bullseye: resolved (fixed in 2.1.2+dfsg1-1)
debian
CVE-2020-4033P4LOWCVSS 3.1fixed in freerdp2 2.1.2+dfsg1-1 (bookworm)2020
CVE-2020-4033 [LOW] CVE-2020-4033: freerdp2 - In FreeRDP before version 2.1.2, there is an out of bounds read in RLEDECOMPRESS...
In FreeRDP before version 2.1.2, there is an out of bounds read in RLEDECOMPRESS. All FreeRDP based clients with sessions with color depth < 32 are affected. This is fixed in version 2.1.2.
Scope: local
bookworm: resolved (fixed in 2.1.2+dfsg1-1)
bullseye: resolved (fixed in 2.1.2+dfsg1-1)
debian
CVE-2020-11522P4MEDIUMCVSS 6.5fixed in freerdp2 2.1.1+dfsg1-1 (bookworm)2020
CVE-2020-11522 [MEDIUM] CVE-2020-11522: freerdp2 - libfreerdp/gdi/gdi.c in FreeRDP > 1.0 through 2.0.0-rc4 has an Out-of-bounds Rea...
libfreerdp/gdi/gdi.c in FreeRDP > 1.0 through 2.0.0-rc4 has an Out-of-bounds Read.
Scope: local
bookworm: resolved (fixed in 2.1.1+dfsg1-1)
bullseye: resolved (fixed in 2.1.1+dfsg1-1)
debian
CVE-2020-11047P4MEDIUMCVSS 5.5fixed in freerdp2 2.1.1+dfsg1-1 (bookworm)2020
CVE-2020-11047 [MEDIUM] CVE-2020-11047: freerdp2 - In FreeRDP after 1.1 and before 2.0.0, there is an out-of-bounds read in autodet...
In FreeRDP after 1.1 and before 2.0.0, there is an out-of-bounds read in autodetect_recv_bandwidth_measure_results. A malicious server can extract up to 8 bytes of client memory with a manipulated message by providing a short input and reading the measurement result data. This has been patched in 2.0.0.
Scope: local
bookworm: resolved (fixed in 2.1.1+dfsg1-1)
bul
debian
CVE-2022-39347P4LOWCVSS 2.6fixed in freerdp2 2.9.0+dfsg1-1 (bookworm)2022
CVE-2022-39347 [LOW] CVE-2022-39347: freerdp2 - FreeRDP is a free remote desktop protocol library and clients. Affected versions...
FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing path canonicalization and base path check for `drive` channel. A malicious server can trick a FreeRDP based client to read files outside the shared directory. This issue has been addressed in version 2.9.0 and all users are advised to upgrade. Users unable to upgr
debian
CVE-2020-11038P4MEDIUMCVSS 6.9fixed in freerdp2 2.1.1+dfsg1-1 (bookworm)2020
CVE-2020-11038 [MEDIUM] CVE-2020-11038: freerdp2 - In FreeRDP less than or equal to 2.0.0, an Integer Overflow to Buffer Overflow e...
In FreeRDP less than or equal to 2.0.0, an Integer Overflow to Buffer Overflow exists. When using /video redirection, a manipulated server can instruct the client to allocate a buffer with a smaller size than requested due to an integer overflow in size calculation. With later messages, the server can manipulate the client to write data out of bound to the previo
debian
CVE-2026-22851P4MEDIUMCVSS 6.9fixed in freerdp3 3.20.2+dfsg-1 (forky)2026
CVE-2026-22851 [MEDIUM] CVE-2026-22851: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1...
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a race condition between the RDPGFX dynamic virtual channel thread and the SDL render thread leads to a heap use-after-free. Specifically, an escaped pointer to sdl->primary (SDL_Surface) is accessed after it has been freed during RDPGFX ResetGraphics handling. This vulnerability is
debian
CVE-2020-11096P4LOWCVSS 3.5fixed in freerdp2 2.1.2+dfsg1-1 (bookworm)2020
CVE-2020-11096 [LOW] CVE-2020-11096: freerdp2 - In FreeRDP before version 2.1.2, there is a global OOB read in update_read_cache...
In FreeRDP before version 2.1.2, there is a global OOB read in update_read_cache_bitmap_v3_order. As a workaround, one can disable bitmap cache with -bitmap-cache (default). This is fixed in version 2.1.2.
Scope: local
bookworm: resolved (fixed in 2.1.2+dfsg1-1)
bullseye: resolved (fixed in 2.1.2+dfsg1-1)
debian
CVE-2020-11042P4MEDIUMCVSS 5.5fixed in freerdp2 2.1.1+dfsg1-1 (bookworm)2020
CVE-2020-11042 [MEDIUM] CVE-2020-11042: freerdp2 - In FreeRDP greater than 1.1 and before 2.0.0, there is an out-of-bounds read in ...
In FreeRDP greater than 1.1 and before 2.0.0, there is an out-of-bounds read in update_read_icon_info. It allows reading a attacker-defined amount of client memory (32bit unsigned -> 4GB) to an intermediate buffer. This can be used to crash the client or store information for later retrieval. This has been patched in 2.0.0.
Scope: local
bookworm: resolved (fixed
debian
CVE-2026-26271P4MEDIUMCVSS 5.5fixed in freerdp3 3.23.0+dfsg-1 (forky)2026
CVE-2026-26271 [MEDIUM] CVE-2026-26271: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to versio...
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, a buffer overread in `freerdp_image_copy_from_icon_data()` (libfreerdp/codec/color.c) can be triggered by crafted RDP Window Icon (TS_ICON_INFO) data. The bug is reachable over the network when a client processes icon data from an RDP server (or from a man-in-the-middle). Ve
debian
CVE-2026-33995P4MEDIUMCVSS 5.3fixed in freerdp3 3.24.2+dfsg-1 (forky)2026
CVE-2026-33995 [MEDIUM] CVE-2026-33995: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to versio...
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, a double-free vulnerability in kerberos_AcceptSecurityContext() and kerberos_InitializeSecurityContextA() (WinPR, winpr/libwinpr/sspi/Kerberos/kerberos.c) can cause a crash in any FreeRDP clients on systems where Kerberos and/or Kerberos U2U is configured (Samba AD member, o
debian
CVE-2020-11019P4MEDIUMCVSS 4.3fixed in freerdp2 2.1.1+dfsg1-1 (bookworm)2020
CVE-2020-11019 [MEDIUM] CVE-2020-11019: freerdp2 - In FreeRDP less than or equal to 2.0.0, when running with logger set to "WLOG_TR...
In FreeRDP less than or equal to 2.0.0, when running with logger set to "WLOG_TRACE", a possible crash of application could occur due to a read of an invalid array index. Data could be printed as string to local terminal. This has been fixed in 2.1.0.
Scope: local
bookworm: resolved (fixed in 2.1.1+dfsg1-1)
bullseye: resolved (fixed in 2.1.1+dfsg1-1)
debian
CVE-2026-33987P4HIGHCVSS 7.1fixed in freerdp3 3.24.2+dfsg-1 (forky)2026
CVE-2026-33987 [HIGH] CVE-2026-33987: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to versio...
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, in persistent_cache_read_entry_v3() in libfreerdp/cache/persistent.c, persistent->bmpSize is updated before winpr_aligned_recalloc(). If realloc fails, bmpSize is inflated while bmpData points to the old buffer. This issue has been patched in version 3.24.2.
Scope: local
bookw
debian
CVE-2025-4478P4LOWCVSS 6.5fixed in freerdp3 3.15.0+dfsg-2.1 (forky)2025
CVE-2025-4478 [MEDIUM] CVE-2025-4478: freerdp2 - A flaw was found in the FreeRDP used by Anaconda's remote install feature, where...
A flaw was found in the FreeRDP used by Anaconda's remote install feature, where a crafted RDP packet could trigger a segmentation fault. This issue causes the service to crash and remain defunct, resulting in a denial of service. It occurs pre-boot and is likely due to a NULL pointer dereference. Rebooting is required to recover the system.
Scope: local
bookworm:
debian