CVE-2024-32041: FreeRDP OutOfBound Read in zgfx_decompress_segment
Published Apr 22, 2024
·Updated
FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients that use a version of FreeRDP prior to 3.5.0 or 2.11.6 are vulnerable to out-of-bounds read. Versions 3.5.0 and 2.11.6 patch the issue. As a workaround, deactivate /gfx (on by default, set /bpp or /rfx options instead.
Affected Software
9 affected componentsFixes available
redhat/FreeRDP<3.5.0
3.5.0
redhat/FreeRDP<2.11.6
2.11.6
FreeRDP freerdp<2.11.6
FreeRDP freerdp>=3.0.0<3.5.0
Fedoraproject Fedora=38
Fedoraproject Fedora=39
Fedoraproject Fedora=40
debian/freerdp2<=2.3.0+dfsg1-2+deb11u1, <=2.10.0+dfsg1-1
2.3.0+dfsg1-2+deb11u3
debian/freerdp3
3.15.0+dfsg-2
Remediation
Event History
Apr 22, 2024
CVE Published
via MITRE·08:39 PM
Data Sourced
via MITRE·08:39 PM
DescriptionSeverityWeakness
Mar 15, 2025
Data Sourced
via Ubuntu·04:36 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·04:37 PM
Description
May 2, 2025
Data Sourced
via Debian·04:46 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-32041?
CVE-2024-32041 has a high severity due to the potential for out-of-bounds read vulnerabilities in FreeRDP.
2
How do I fix CVE-2024-32041?
To fix CVE-2024-32041, upgrade FreeRDP to version 3.5.0 or 2.11.6 or later.
3
Which versions of FreeRDP are affected by CVE-2024-32041?
FreeRDP versions prior to 3.5.0 and 2.11.6 are affected by CVE-2024-32041.
4
What workaround can I use for CVE-2024-32041?
As a workaround for CVE-2024-32041, you can deactivate the '/gfx' option in FreeRDP.
5
Is there a known exploit for CVE-2024-32041?
As of now, there are no reported exploits specifically targeting CVE-2024-32041.