CVE-2023-40589: FreeRDP Global-Buffer-Overflow in ncrush_decompress
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. In affected versions there is a Global-Buffer-Overflow in the ncrushdecompress function. Feeding crafted input into this function can trigger the overflow which has only been shown to cause a crash. This issue has been addressed in versions 2.11.0 and 3.0.0-beta3. Users are advised to upgrade. There are no known workarounds for this issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-40589?
CVE-2023-40589 is a vulnerability in the FreeRDP software that allows a global buffer overflow in the ncrush_decompress function.
What is the severity of CVE-2023-40589?
CVE-2023-40589 has a severity level of 7.5 (high).
How does CVE-2023-40589 affect FreeRDP?
CVE-2023-40589 affects versions of FreeRDP up to and including 2.11.0 and 3.0.0-beta1 and beta2.
How can I fix CVE-2023-40589?
To fix CVE-2023-40589, you should update to at least version 2.11.2+dfsg1-1 of the freerdp2 package.
Where can I find more information about CVE-2023-40589?
You can find more information about CVE-2023-40589 in the official GitHub commit and security advisories for FreeRDP.