CVE-2023-40569

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versions are subject to an Out-Of-Bounds Write in the `progressive_decompress` function. This issue is likely down to incorrect calculations of the `nXSrc` and `nYSrc` variables. This issue has been addressed in versions 2.11.0 and 3.0.0-beta3. Users are advised to upgrade. there are no known workarounds for this vulnerability.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 28%
Affected Products (NVD)
VendorProductVersion
freerdpfreerdp
𝑥
< 2.11.0
freerdpfreerdp
3.0.0:beta1
freerdpfreerdp
3.0.0:beta2
debiandebian_linux
10.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
freerdp2
bookworm
no-dsa
bullseye
no-dsa
sid
2.11.7+dfsg1-6
fixed
trixie
2.11.7+dfsg1-6
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
freerdp2
bionic
Fixed 2.2.0+dfsg1-0ubuntu0.18.04.4+esm1
released
focal
Fixed 2.2.0+dfsg1-0ubuntu0.20.04.5
released
jammy
Fixed 2.6.1+dfsg1-3ubuntu2.4
released
lunar
Fixed 2.10.0+dfsg1-1ubuntu0.2
released
mantic
Fixed 2.10.0+dfsg1-1.1ubuntu1
released
trusty
ignored
xenial
ignored
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
freerdp
suse enterprise desktop 15 SP4
2.4.0-150400.3.23.1
fixed
suse enterprise desktop 15 SP5
2.4.0-150400.3.23.1
fixed
suse enterprise sap 15 SP4
2.4.0-150400.3.23.1
fixed
suse enterprise sap 15 SP5
2.4.0-150400.3.23.1
fixed
suse enterprise server 15 SP4
2.4.0-150400.3.23.1
fixed
suse enterprise server 15 SP5
2.4.0-150400.3.23.1
fixed
suse enterprise workstation 15 SP4
2.4.0-150400.3.23.1
fixed
suse enterprise workstation 15 SP5
2.4.0-150400.3.23.1
fixed
freerdp-devel
suse enterprise desktop 15 SP4
2.4.0-150400.3.23.1
fixed
suse enterprise desktop 15 SP5
2.4.0-150400.3.23.1
fixed
suse enterprise sap 15 SP4
2.4.0-150400.3.23.1
fixed
suse enterprise sap 15 SP5
2.4.0-150400.3.23.1
fixed
suse enterprise server 15 SP4
2.4.0-150400.3.23.1
fixed
suse enterprise server 15 SP5
2.4.0-150400.3.23.1
fixed
suse enterprise workstation 15 SP4
2.4.0-150400.3.23.1
fixed
suse enterprise workstation 15 SP5
2.4.0-150400.3.23.1
fixed
freerdp-proxy
suse enterprise desktop 15 SP4
2.4.0-150400.3.23.1
fixed
suse enterprise desktop 15 SP5
2.4.0-150400.3.23.1
fixed
suse enterprise sap 15 SP4
2.4.0-150400.3.23.1
fixed
suse enterprise sap 15 SP5
2.4.0-150400.3.23.1
fixed
suse enterprise server 15 SP4
2.4.0-150400.3.23.1
fixed
suse enterprise server 15 SP5
2.4.0-150400.3.23.1
fixed
suse enterprise workstation 15 SP4
2.4.0-150400.3.23.1
fixed
suse enterprise workstation 15 SP5
2.4.0-150400.3.23.1
fixed
libfreerdp2
suse enterprise desktop 15 SP4
2.4.0-150400.3.23.1
fixed
suse enterprise desktop 15 SP5
2.4.0-150400.3.23.1
fixed
suse enterprise sap 15 SP4
2.4.0-150400.3.23.1
fixed
suse enterprise sap 15 SP5
2.4.0-150400.3.23.1
fixed
suse enterprise server 15 SP4
2.4.0-150400.3.23.1
fixed
suse enterprise server 15 SP5
2.4.0-150400.3.23.1
fixed
suse enterprise workstation 15 SP4
2.4.0-150400.3.23.1
fixed
suse enterprise workstation 15 SP5
2.4.0-150400.3.23.1
fixed
libwinpr2
suse enterprise desktop 15 SP4
2.4.0-150400.3.23.1
fixed
suse enterprise desktop 15 SP5
2.4.0-150400.3.23.1
fixed
suse enterprise sap 15 SP4
2.4.0-150400.3.23.1
fixed
suse enterprise sap 15 SP5
2.4.0-150400.3.23.1
fixed
suse enterprise server 15 SP4
2.4.0-150400.3.23.1
fixed
suse enterprise server 15 SP5
2.4.0-150400.3.23.1
fixed
suse enterprise workstation 15 SP4
2.4.0-150400.3.23.1
fixed
suse enterprise workstation 15 SP5
2.4.0-150400.3.23.1
fixed
winpr2-devel
suse enterprise desktop 15 SP4
2.4.0-150400.3.23.1
fixed
suse enterprise desktop 15 SP5
2.4.0-150400.3.23.1
fixed
suse enterprise sap 15 SP4
2.4.0-150400.3.23.1
fixed
suse enterprise sap 15 SP5
2.4.0-150400.3.23.1
fixed
suse enterprise server 15 SP4
2.4.0-150400.3.23.1
fixed
suse enterprise server 15 SP5
2.4.0-150400.3.23.1
fixed
suse enterprise workstation 15 SP4
2.4.0-150400.3.23.1
fixed
suse enterprise workstation 15 SP5
2.4.0-150400.3.23.1
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
freerdp
RHEL 9
2:2.11.2-1.el9
fixed
freerdp-devel
RHEL 9
2:2.11.2-1.el9
fixed
freerdp-libs
RHEL 9
2:2.11.2-1.el9
fixed
libwinpr
RHEL 9
2:2.11.2-1.el9
fixed
libwinpr-devel
RHEL 9
2:2.11.2-1.el9
fixed