Skip to content

RDP client: Read of uninitialized memory with parallel port redirection

Low
akallabeth published GHSA-c45q-wcpg-mxjq Oct 12, 2022

Package

FreeRDP (C)

Affected versions

<= 2.8.0

Patched versions

2.8.1

Description

Impact

FreeRDP based clients on unix systems using /parallel command line switch might read uninitialized data and send it to the server the client is currently connected to

FreeRDP based server implementations are not affected.

Patches

Upgrade to 2.8.1

Workarounds

Do not use parallel port redirection (/parallel command line switch)

Issue Reporter

Reported by BT5

For more information

If you have any questions or comments about this advisory:

Severity

Low

CVE ID

CVE-2022-39282

Weaknesses

No CWEs

Credits