CVE-2023-40569: Out-Of-Bounds Write in FreeRDP
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versions are subject to an Out-Of-Bounds Write in the progressivedecompress function. This issue is likely down to incorrect calculations of the nXSrc and nYSrc variables. This issue has been addressed in versions 2.11.0 and 3.0.0-beta3. Users are advised to upgrade. there are no known workarounds for this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-40569?
CVE-2023-40569 is an Out-Of-Bounds Write vulnerability in FreeRDP.
How does CVE-2023-40569 impact FreeRDP?
CVE-2023-40569 allows an attacker to write beyond the boundaries of a buffer in the progressive_decompress function, potentially leading to remote code execution.
What is the severity of CVE-2023-40569?
CVE-2023-40569 has a severity rating of 9.8 (Critical).
Which versions of FreeRDP are affected by CVE-2023-40569?
Versions up to and including 2.11.0, 3.0.0-beta1, and 3.0.0-beta2 of FreeRDP are affected by CVE-2023-40569.
How can I fix CVE-2023-40569 in FreeRDP?
To fix CVE-2023-40569, it is recommended to update FreeRDP to a version that includes the relevant security patches.