First published: Thu Aug 31 2023(Updated: )
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versions are subject to an Out-Of-Bounds Write in the `writePixelBGRX` function. This issue is likely down to incorrect calculations of the `nHeight` and `srcStep` variables. This issue has been addressed in version 3.0.0-beta3. Users are advised to upgrade. There are no known workarounds for this issue.
Credit: security-advisories@github.com security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
=3.0.0-beta1 | ||
=3.0.0-beta2 | ||
FreeRDP FreeRDP | =3.0.0-beta1 | |
FreeRDP FreeRDP | =3.0.0-beta2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-40574 is a vulnerability in the FreeRDP Remote Desktop Protocol (RDP) implementation that allows for an Out-Of-Bounds Write in the writePixelBGRX function.
The severity of CVE-2023-40574 is critical, with a severity score of 9.8.
FreeRDP versions 3.0.0-beta1 and 3.0.0-beta2 are affected by CVE-2023-40574.
CVE-2023-40574 in FreeRDP can lead to an Out-Of-Bounds Write vulnerability due to incorrect calculations in the writePixelBGRX function.
To fix CVE-2023-40574, it is recommended to update to a version of FreeRDP that includes the necessary security patches.