First published: Wed Oct 12 2022(Updated: )
FreeRDP is a free remote desktop protocol library and clients. All FreeRDP based clients when using the `/video` command line switch might read uninitialized data, decode it as audio/video and display the result. FreeRDP based server implementations are not affected. This issue has been patched in version 2.8.1. If you cannot upgrade do not use the `/video` switch.
Credit: security-advisories@github.com security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
FreeRDP FreeRDP | <2.8.1 | |
Fedoraproject Fedora | =35 | |
Fedoraproject Fedora | =36 | |
Fedoraproject Fedora | =37 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-39283 is a vulnerability in the FreeRDP remote desktop protocol library and clients that allows uninitialized data to be decoded as audio/video when using the `/video` command line switch.
All FreeRDP based clients are affected by CVE-2022-39283 when using the `/video` command line switch.
No, FreeRDP based server implementations are not affected by CVE-2022-39283.
CVE-2022-39283 has a severity rating of 7.5 (High).
To fix CVE-2022-39283, update FreeRDP to version 2.8.1 or apply the appropriate patch provided by the FreeRDP project.