REDHAT-BUG-2510125: Buffer Overflow
FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES backends that fail to validate the FramesPerPacket parameter from RDP servers. Attackers can supply a malicious FramesPerPacket value causing allocation size wraparound, resulting in heap-based buffer overflow on ALSA or denial of service on all platforms.
Affected Software
Event History
Frequently Asked Questions
What does an attacker need to control to exploit this issue?
The attacker needs to operate or control an RDP server that can send a malicious FramesPerPacket value through the audio input redirection channel.
Which environments face heap-based buffer-overflow risk rather than only denial of service?
The heap-based buffer overflow is identified on the ALSA backend. The issue can cause denial of service on all affected platforms and audio backends.
Which FreeRDP versions need to be remediated?
FreeRDP versions before 3.29.0 are affected. Updating to 3.29.0 or later addresses the described vulnerable behavior.