CVE-2023-39352

MEDIUM

Freerdp < 2.11.0 - Out-of-Bounds Write

Title source: rule
STIX 2.1

Description

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versions are subject to an invalid offset validation leading to Out Of Bound Write. This can be triggered when the values `rect->left` and `rect->top` are exactly equal to `surface->width` and `surface->height`. eg. `rect->left` == `surface->width` && `rect->top` == `surface->height`. In practice this should cause a crash. This issue has been addressed in versions 2.11.0 and 3.0.0-beta3. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Scores

CVSS v3 5.3
EPSS 0.0019
EPSS Percentile 40.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Details

CWE
CWE-787
Status published
Products (6)
debian/debian_linux 10.0
fedoraproject/fedora 37
fedoraproject/fedora 38
fedoraproject/fedora 39
freerdp/freerdp 3.0.0 beta1 (2 CPE variants)
freerdp/freerdp < 2.11.0
Published Aug 31, 2023
Tracked Since Feb 18, 2026