CVE-2022-39318: Division by zero in urbdrc channel in FreeRDP
FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing input validation in urbdrc channel. A malicious server can trick a FreeRDP based client to crash with division by zero. This issue has been addressed in version 2.9.0. All users are advised to upgrade. Users unable to upgrade should not use the /usb redirection switch.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-39318?
CVE-2022-39318 is a vulnerability in FreeRDP that allows a malicious server to crash a FreeRDP based client with a division by zero error.
What is the severity of CVE-2022-39318?
The severity of CVE-2022-39318 is medium with a CVSS score of 5.7.
Which versions of FreeRDP are affected by CVE-2022-39318?
Affected versions of FreeRDP are up to, but excluding, version 2.9.0.
How can I fix CVE-2022-39318 in FreeRDP?
To fix CVE-2022-39318, update FreeRDP to version 2.9.0 or later.
Is there any additional information available for CVE-2022-39318?
Yes, you can find more information about CVE-2022-39318 in the references provided: [link1], [link2], [link3].