First published: Wed Oct 04 2023(Updated: )
It was discovered that FreeRDP did not properly manage certain inputs. A malicious server could use this issue to cause FreeRDP clients to crash, resulting in a denial of service, or possibly obtain sensitive information. (CVE-2023-39350, CVE-2023-39351, CVE-2023-39353, CVE-2023-39354, CVE-2023-40181, CVE-2023-40188, CVE-2023-40589) It was discovered that FreeRDP did not properly manage certain inputs. A malicious server could use this issue to cause FreeRDP clients to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2023-40186, CVE-2023-40567, CVE-2023-40569)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/libfreerdp2-2 | <2.10.0+dfsg1-1ubuntu0.2 | 2.10.0+dfsg1-1ubuntu0.2 |
=23.04 | ||
All of | ||
ubuntu/libfreerdp2-2 | <2.6.1+dfsg1-3ubuntu2.4 | 2.6.1+dfsg1-3ubuntu2.4 |
=22.04 | ||
All of | ||
ubuntu/libwinpr2-2 | <2.6.1+dfsg1-3ubuntu2.4 | 2.6.1+dfsg1-3ubuntu2.4 |
=22.04 | ||
All of | ||
ubuntu/libwinpr2-dev | <2.6.1+dfsg1-3ubuntu2.4 | 2.6.1+dfsg1-3ubuntu2.4 |
=22.04 | ||
All of | ||
ubuntu/libfreerdp2-2 | <2.2.0+dfsg1-0ubuntu0.20.04.5 | 2.2.0+dfsg1-0ubuntu0.20.04.5 |
=20.04 | ||
All of | ||
ubuntu/libwinpr2-2 | <2.2.0+dfsg1-0ubuntu0.20.04.5 | 2.2.0+dfsg1-0ubuntu0.20.04.5 |
=20.04 | ||
All of | ||
ubuntu/libwinpr2-dev | <2.2.0+dfsg1-0ubuntu0.20.04.5 | 2.2.0+dfsg1-0ubuntu0.20.04.5 |
=20.04 | ||
All of | ||
ubuntu/libfreerdp2-2 | <2.2.0+dfsg1-0ubuntu0.18.04.4+esm1 | 2.2.0+dfsg1-0ubuntu0.18.04.4+esm1 |
=18.04 | ||
All of | ||
ubuntu/libwinpr2-2 | <2.2.0+dfsg1-0ubuntu0.18.04.4+esm1 | 2.2.0+dfsg1-0ubuntu0.18.04.4+esm1 |
=18.04 | ||
All of | ||
ubuntu/libwinpr2-dev | <2.2.0+dfsg1-0ubuntu0.18.04.4+esm1 | 2.2.0+dfsg1-0ubuntu0.18.04.4+esm1 |
=18.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Contains the following vulnerabilities)
The vulnerability ID for this advisory is USN-6401-1.
The severity of the FreeRDP vulnerabilities is not specified in the provided information.
The affected software is libfreerdp2-2, libwinpr2-2, libwinpr2-dev, on Ubuntu versions 23.04, 22.04, 20.04, and 18.04.
To fix the FreeRDP vulnerabilities, update the libfreerdp2-2, libwinpr2-2, and libwinpr2-dev packages to the specified versions.
You can find more information about the FreeRDP vulnerabilities in the provided references: [CVE-2023-39351](https://ubuntu.com/security/CVE-2023-39351), [CVE-2023-40186](https://ubuntu.com/security/CVE-2023-40186), [CVE-2023-40569](https://ubuntu.com/security/CVE-2023-40569).