CVE-2024-32460: FreeRDP Out-Of-Bounds Read in interleaved_decompress
FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based based clients using /bpp:32 legacy GDI drawing path with a version of FreeRDP prior to 3.5.0 or 2.11.6 are vulnerable to out-of-bounds read. Versions 3.5.0 and 2.11.6 patch the issue. As a workaround, use modern drawing paths (e.g. /rfx or /gfx options). The workaround requires server side support.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-32460?
CVE-2024-32460 is considered a high severity vulnerability due to its potential to allow an out-of-bounds read which could lead to information disclosure.
How do I fix CVE-2024-32460?
To fix CVE-2024-32460, update FreeRDP to version 3.5.0 or 2.11.6 or later.
What software is affected by CVE-2024-32460?
CVE-2024-32460 affects FreeRDP clients using the legacy GDI drawing path with versions prior to 3.5.0 or 2.11.6.
Is there a workaround for CVE-2024-32460?
A temporary workaround for CVE-2024-32460 may involve avoiding the use of the `/bpp:32` option with affected FreeRDP versions.
What platforms are impacted by CVE-2024-32460?
CVE-2024-32460 impacts various Linux distributions including Ubuntu and Debian where FreeRDP versions are utilized.