CVE-2022-39283: FreeRDP may read and display out of bounds data
FreeRDP is a free remote desktop protocol library and clients. All FreeRDP based clients when using the /video command line switch might read uninitialized data, decode it as audio/video and display the result. FreeRDP based server implementations are not affected. This issue has been patched in version 2.8.1. If you cannot upgrade do not use the /video switch.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-39283?
CVE-2022-39283 is a vulnerability in the FreeRDP remote desktop protocol library and clients that allows uninitialized data to be decoded as audio/video when using the `/video` command line switch.
Which FreeRDP based clients are affected by CVE-2022-39283?
All FreeRDP based clients are affected by CVE-2022-39283 when using the `/video` command line switch.
Are FreeRDP based server implementations affected by CVE-2022-39283?
No, FreeRDP based server implementations are not affected by CVE-2022-39283.
How severe is CVE-2022-39283?
CVE-2022-39283 has a severity rating of 7.5 (High).
How can I fix CVE-2022-39283?
To fix CVE-2022-39283, update FreeRDP to version 2.8.1 or apply the appropriate patch provided by the FreeRDP project.