CVE-2023-40567: Out-Of-Bounds Write in FreeRDP
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versions are subject to an Out-Of-Bounds Write in the cleardecompressbandsdata function in which there is no offset validation. Abuse of this vulnerability may lead to an out of bounds write. This issue has been addressed in versions 2.11.0 and 3.0.0-beta3. Users are advised to upgrade. there are no known workarounds for this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-40567?
CVE-2023-40567 is a vulnerability in the FreeRDP software that allows for an Out-Of-Bounds Write in the clear_decompress_bands_data function.
What is the severity of CVE-2023-40567?
The severity of CVE-2023-40567 is critical with a CVSS score of 9.8.
How does CVE-2023-40567 affect FreeRDP?
CVE-2023-40567 affects versions up to 2.11.0 of FreeRDP and versions 3.0.0-beta1 and 3.0.0-beta2 of FreeRDP.
How can CVE-2023-40567 be exploited?
CVE-2023-40567 can be exploited by abusing the vulnerability to cause an out of bounds write, potentially leading to a denial of service or remote code execution.
How can I fix CVE-2023-40567?
To fix CVE-2023-40567, it is recommended to update to version 2.11.2+dfsg1-1 or apply the appropriate remedy for your specific distribution.