CVE-2023-40575: Out-Of-Bounds Read in FreeRDP
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versions are subject to an Out-Of-Bounds Read in the generalYUV444ToRGB8uP3AC4RBGRX function. This issue is likely down to insufficient data for the pSrc variable and results in crashes. This issue has been addressed in version 3.0.0-beta3. Users are advised to upgrade. There are no known workarounds for this issue.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-40575?
CVE-2023-40575 is a vulnerability in FreeRDP, a free implementation of the Remote Desktop Protocol (RDP), that allows for an Out-of-Bounds Read in the `general_YUV444ToRGB_8u_P3AC4R_BGRX` function.
What is the severity of CVE-2023-40575?
The severity of CVE-2023-40575 is critical with a severity score of 9.1.
Which versions of FreeRDP are affected by CVE-2023-40575?
FreeRDP versions 3.0.0-beta1 and 3.0.0-beta2 are affected by CVE-2023-40575.
How does CVE-2023-40575 impact FreeRDP?
CVE-2023-40575 can lead to an out-of-bounds read vulnerability in FreeRDP, potentially resulting in information disclosure or remote code execution.
How can I fix CVE-2023-40575?
To fix CVE-2023-40575, users should upgrade to a version of FreeRDP that includes the necessary patches or security updates.