安全公告/【CVE-2023-39352】

基本信息

漏洞名称:
受影响操作系统:Asianux
危险等级:超危
影响源码包:freerdp
CVSS评分:9.8
发现日期:2023-09-25
修复版本:freerdp-2.11.1-1

漏洞描述

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versions are subject to an invalid offset validation leading to Out Of Bound Write. This can be triggered when the values `rect->left` and `rect->top` are exactly equal to `surface->width` and `surface->height`. eg. `rect->left` == `surface->width` && `rect->top` == `surface->height`. In practice this should cause a crash. This issue has been addressed in versions 2.11.0 and 3.0.0-beta3. Users are advised to upgrade. There are no known workarounds for this vulnerability.

修复方式

yum update PackageName

漏洞判定

执行命令yum info PackageName获取软件包版本号,版本小于修复版本,则受此漏洞影响,版本大于等于修复版本,则此漏洞已修复

补丁

参考

https://gitee.com/src-openeuler/freerdp/issues/I7XN5M
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39352
https://nvd.nist.gov/vuln/detail/CVE-2023-39352