FreeRDP 2.0.0-rc3 contains an out of bounds read vulnerability in drdynvcprocesscapabilityrequest function in channels/drdynvc/client/drdynvcmain.c file. To exploit this RDPClient must connect to the rdp server with the echo option. This can lead to a two-byte outbound reading from the client memory.
References: https://github.com/FreeRDP/FreeRDP/issues/4866
Upstream Patch: https://github.com/FreeRDP/FreeRDP/pull/4871/commits/baee520e3dd9be6511c45a14c5f5e77784de1471
In FreeRDP less than or equal to 2.0.0, a possible resource exhaustion vulnerability can be performed. Malicious clients could trigger out of bound reads causing memory allocation with random size. This has been fixed in 2.1.0.