FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients prior to version 3.5.1 are vulnerable to out-of-bounds read. This occurs when `WCHAR` string is read with twice the size it has and converted to `UTF-8`, `base64` decoded. The string is only used to compare against the redirection server certificate. Version 3.5.1 contains a patch for the issue. No known workarounds are available.
History

Tue, 04 Feb 2025 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Fedoraproject
Fedoraproject fedora
CPEs cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:*
Vendors & Products Fedoraproject
Fedoraproject fedora

Wed, 13 Nov 2024 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat
Redhat enterprise Linux
CPEs cpe:/a:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-02-13T17:52:17.136Z

Reserved: 2024-04-16T14:15:26.878Z

Link: CVE-2024-32662

cve-icon Vulnrichment

Updated: 2024-08-02T02:13:40.282Z

cve-icon NVD

Status : Analyzed

Published: 2024-04-23T21:15:48.200

Modified: 2025-02-04T17:44:06.430

Link: CVE-2024-32662

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-04-23T00:00:00Z

Links: CVE-2024-32662 - Bugzilla