CVE-2023-40186: IntegerOverflow leading to Out-Of-Bound Write Vulnerability in FreeRDP
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versions are subject to an IntegerOverflow leading to Out-Of-Bound Write Vulnerability in the gdiCreateSurface function. This issue affects FreeRDP based clients only. FreeRDP proxies are not affected as image decoding is not done by a proxy. This issue has been addressed in versions 2.11.0 and 3.0.0-beta3. Users are advised to upgrade. There are no known workarounds for this issue.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-40186?
CVE-2023-40186 is an IntegerOverflow leading to Out-Of-Bound Write Vulnerability in the `gdi_CreateSurface` function of FreeRDP.
Which software versions are affected by CVE-2023-40186?
Versions up to and excluding 2.11.0 of FreeRDP and version 3.0.0-beta1 and 3.0.0-beta2 of FreeRDP are affected by CVE-2023-40186.
What is the severity rating of CVE-2023-40186?
CVE-2023-40186 has a severity rating of 9.8 (Critical).
How can I fix CVE-2023-40186?
To fix CVE-2023-40186, update to FreeRDP version 2.11.2+dfsg1-1 or a later version as recommended by the vendor.
Is there any additional information available about CVE-2023-40186?
Additional information about CVE-2023-40186 can be found at the following references: [link1], [link2], [link3].