Skip to content

Out of bound read in zgfx decoder

Low
bmiklautz published GHSA-5w4j-mrrh-jjrm Nov 16, 2022

Package

FreeRDP (C)

Affected versions

<= 2.8.1

Patched versions

2.9.0

Description

Impact

Out of bound read in ZGFX decoder
A malicious server can trick a FreeRDP based client to read out of bound data and try to decode it.

Patches

2.9.0

Workarounds

Is there a way for users to fix or remediate the vulnerability without upgrading?

Issue Reporter

Reported by 'Team BT5 (BoB 11th)'

For more information

If you have any questions or comments about this advisory:

Severity

Low

CVE ID

CVE-2022-39316

Weaknesses

No CWEs

Credits