Skip to main content

Out-of-bounds Read

CVE-2023-40181

Severity High
Score 9.1/10

Summary

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. In affected versions through 2.10.0, and 3.0.0-beta1 through 3.0.0-beta2 are subject to an Integer-Underflow leading to Out-Of-Bound Read in the `zgfx_decompress_segment` function. In the context of `CopyMemory`, it's possible to read data beyond the transmitted packet range and likely cause a crash.

  • LOW
  • NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • NONE
  • HIGH
  • HIGH

CWE-125 - Out-of-Bounds Read

Out-of-bounds read is a vulnerability that allows access to memory beyond the authorized accessible location. Such a vulnerability compromises the confidentiality of the trusted environment in the application and enables an attacker to launch further attacks by leveraging the exposed information.

Advisory Timeline

  • Published