CVE-2023-39350: Incorrect offset calculation leading to denial of service in FreeRDP
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. This issue affects Clients only. Integer underflow leading to DOS (e.g. abort due to WINPRASSERT with default compilation flags). When an insufficient blockLen is provided, and proper length validation is not performed, an Integer Underflow occurs, leading to a Denial of Service (DOS) vulnerability. This issue has been addressed in versions 2.11.0 and 3.0.0-beta3. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-39350?
CVE-2023-39350 is a vulnerability in FreeRDP, an open-source implementation of the Remote Desktop Protocol (RDP), that can result in denial-of-service (DOS) attacks.
Who is affected by CVE-2023-39350?
Only the clients of FreeRDP version up to 2.11.0 and version 3.0.0-beta1 and beta2 are affected by CVE-2023-39350.
What is the severity level of CVE-2023-39350?
The severity level of CVE-2023-39350 is high with a CVSS score of 7.5 out of 10.
How can I fix CVE-2023-39350?
To fix CVE-2023-39350, it is recommended to update to FreeRDP version 2.11.2 or later.
Where can I find more information about CVE-2023-39350?
You can find more information about CVE-2023-39350 on the GitHub security advisory page and the CVE details page.