Total vulnerabilities in the database
FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients that use a version of FreeRDP prior to 3.5.0 or 2.11.6 and have connections to servers using the NSC
codec are vulnerable to integer underflow. Versions 3.5.0 and 2.11.6 patch the issue. As a workaround, do not use the NSC codec (e.g. use -nsc
).
Software | From | Fixed in |
---|---|---|
freerdp / freerdp | 3.0.0 | 3.5.0 |
freerdp / freerdp | - | 2.11.6 |
fedoraproject / fedora | 38 | 38.x |
fedoraproject / fedora | 39 | 39.x |
fedoraproject / fedora | 40 | 40.x |