Skip to content

Missing path sanitation with `drive` channel

Low
bmiklautz published GHSA-c5xq-8v35-pffg Nov 16, 2022

Package

FreeRDP (C)

Affected versions

<= 2.8.1

Patched versions

2.9.0

Description

Impact

Missing path canonicalization and base path check for drive channel
A malicious server can trick a FreeRDP based client to read files outside the shared directory

Patches

2.9.0

Workarounds

Do not use the /drive, /drives or +home-drive redirection switch

Issue Reporter

Reported by 'Team BT5 (BoB 11th)'

For more information

If you have any questions or comments about this advisory:

Severity

Low

CVE ID

CVE-2022-39347

Weaknesses

No CWEs

Credits