{"schema_version":"1.7.2","id":"OESA-2024-1108","modified":"2024-02-02T11:06:52Z","published":"2024-02-02T11:06:52Z","upstream":["CVE-2024-22211"],"summary":"freerdp security update","details":"FreeRDP is a client implementation of the Remote Desktop Protocol (RDP) that follows Microsoft\u0026apos;s open specifications. This package provides the client applications xfreerdp and wlfreerdp.\r\n\r\nSecurity Fix(es):\r\n\r\nFreeRDP is a set of free and open source remote desktop protocol library and clients. In affected versions an integer overflow in `freerdp_bitmap_planar_context_reset` leads to heap-buffer overflow. This affects FreeRDP based clients. FreeRDP based server implementations and proxy are not affected. A malicious server could prepare a `RDPGFX_RESET_GRAPHICS_PDU` to allocate too small buffers, possibly triggering later out of bound read/write. Data extraction over network is not possible, the buffers are used to display an image. This issue has been addressed in version 2.11.5 and 3.2.0. Users are advised to upgrade. there are no know workarounds for this vulnerability.\n(CVE-2024-22211)","affected":[{"package":{"ecosystem":"openEuler:20.03-LTS-SP1","name":"freerdp","purl":"pkg:rpm/openEuler/freerdp\u0026distro=openEuler-20.03-LTS-SP1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.11.1-2.oe1"}]}],"ecosystem_specific":{"aarch64":["freerdp-devel-2.11.1-2.oe1.aarch64.rpm","libwinpr-2.11.1-2.oe1.aarch64.rpm","freerdp-2.11.1-2.oe1.aarch64.rpm","freerdp-debugsource-2.11.1-2.oe1.aarch64.rpm","freerdp-help-2.11.1-2.oe1.aarch64.rpm","freerdp-debuginfo-2.11.1-2.oe1.aarch64.rpm","libwinpr-devel-2.11.1-2.oe1.aarch64.rpm"],"src":["freerdp-2.11.1-2.oe1.src.rpm"],"x86_64":["freerdp-2.11.1-2.oe1.x86_64.rpm","freerdp-debuginfo-2.11.1-2.oe1.x86_64.rpm","freerdp-debugsource-2.11.1-2.oe1.x86_64.rpm","freerdp-help-2.11.1-2.oe1.x86_64.rpm","libwinpr-devel-2.11.1-2.oe1.x86_64.rpm","libwinpr-2.11.1-2.oe1.x86_64.rpm","freerdp-devel-2.11.1-2.oe1.x86_64.rpm"]}},{"package":{"ecosystem":"openEuler:20.03-LTS-SP4","name":"freerdp","purl":"pkg:rpm/openEuler/freerdp\u0026distro=openEuler-20.03-LTS-SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.11.1-2.oe2003sp4"}]}],"ecosystem_specific":{"aarch64":["freerdp-2.11.1-2.oe2003sp4.aarch64.rpm","freerdp-debuginfo-2.11.1-2.oe2003sp4.aarch64.rpm","freerdp-help-2.11.1-2.oe2003sp4.aarch64.rpm","freerdp-devel-2.11.1-2.oe2003sp4.aarch64.rpm","freerdp-debugsource-2.11.1-2.oe2003sp4.aarch64.rpm","libwinpr-2.11.1-2.oe2003sp4.aarch64.rpm","libwinpr-devel-2.11.1-2.oe2003sp4.aarch64.rpm"],"src":["freerdp-2.11.1-2.oe2003sp4.src.rpm"],"x86_64":["freerdp-debugsource-2.11.1-2.oe2003sp4.x86_64.rpm","libwinpr-2.11.1-2.oe2003sp4.x86_64.rpm","freerdp-help-2.11.1-2.oe2003sp4.x86_64.rpm","freerdp-devel-2.11.1-2.oe2003sp4.x86_64.rpm","libwinpr-devel-2.11.1-2.oe2003sp4.x86_64.rpm","freerdp-debuginfo-2.11.1-2.oe2003sp4.x86_64.rpm","freerdp-2.11.1-2.oe2003sp4.x86_64.rpm"]}},{"package":{"ecosystem":"openEuler:22.03-LTS","name":"freerdp","purl":"pkg:rpm/openEuler/freerdp\u0026distro=openEuler-22.03-LTS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.11.1-2.oe2203sp3"}]}],"ecosystem_specific":{"aarch64":["freerdp-debugsource-2.11.1-2.oe2203.aarch64.rpm","freerdp-help-2.11.1-2.oe2203.aarch64.rpm","freerdp-devel-2.11.1-2.oe2203.aarch64.rpm","freerdp-debuginfo-2.11.1-2.oe2203.aarch64.rpm","libwinpr-devel-2.11.1-2.oe2203.aarch64.rpm","libwinpr-2.11.1-2.oe2203.aarch64.rpm","freerdp-2.11.1-2.oe2203.aarch64.rpm","freerdp-debugsource-2.11.1-2.oe2203sp1.aarch64.rpm","libwinpr-devel-2.11.1-2.oe2203sp1.aarch64.rpm","freerdp-devel-2.11.1-2.oe2203sp1.aarch64.rpm","libwinpr-2.11.1-2.oe2203sp1.aarch64.rpm","freerdp-2.11.1-2.oe2203sp1.aarch64.rpm","freerdp-help-2.11.1-2.oe2203sp1.aarch64.rpm","freerdp-debuginfo-2.11.1-2.oe2203sp1.aarch64.rpm","freerdp-debuginfo-2.11.1-2.oe2203sp2.aarch64.rpm","freerdp-help-2.11.1-2.oe2203sp2.aarch64.rpm","freerdp-2.11.1-2.oe2203sp2.aarch64.rpm","freerdp-debugsource-2.11.1-2.oe2203sp2.aarch64.rpm","libwinpr-devel-2.11.1-2.oe2203sp2.aarch64.rpm","libwinpr-2.11.1-2.oe2203sp2.aarch64.rpm","freerdp-devel-2.11.1-2.oe2203sp2.aarch64.rpm","libwinpr-2.11.1-2.oe2203sp3.aarch64.rpm","freerdp-help-2.11.1-2.oe2203sp3.aarch64.rpm","freerdp-devel-2.11.1-2.oe2203sp3.aarch64.rpm","libwinpr-devel-2.11.1-2.oe2203sp3.aarch64.rpm","freerdp-debugsource-2.11.1-2.oe2203sp3.aarch64.rpm","freerdp-debuginfo-2.11.1-2.oe2203sp3.aarch64.rpm","freerdp-2.11.1-2.oe2203sp3.aarch64.rpm"],"src":["freerdp-2.11.1-2.oe2203.src.rpm","freerdp-2.11.1-2.oe2203sp1.src.rpm","freerdp-2.11.1-2.oe2203sp2.src.rpm","freerdp-2.11.1-2.oe2203sp3.src.rpm"],"x86_64":["libwinpr-2.11.1-2.oe2203.x86_64.rpm","freerdp-devel-2.11.1-2.oe2203.x86_64.rpm","freerdp-debugsource-2.11.1-2.oe2203.x86_64.rpm","libwinpr-devel-2.11.1-2.oe2203.x86_64.rpm","freerdp-2.11.1-2.oe2203.x86_64.rpm","freerdp-help-2.11.1-2.oe2203.x86_64.rpm","freerdp-debuginfo-2.11.1-2.oe2203.x86_64.rpm","freerdp-debuginfo-2.11.1-2.oe2203sp1.x86_64.rpm","freerdp-devel-2.11.1-2.oe2203sp1.x86_64.rpm","libwinpr-2.11.1-2.oe2203sp1.x86_64.rpm","freerdp-help-2.11.1-2.oe2203sp1.x86_64.rpm","freerdp-2.11.1-2.oe2203sp1.x86_64.rpm","libwinpr-devel-2.11.1-2.oe2203sp1.x86_64.rpm","freerdp-debugsource-2.11.1-2.oe2203sp1.x86_64.rpm","freerdp-debugsource-2.11.1-2.oe2203sp2.x86_64.rpm","freerdp-help-2.11.1-2.oe2203sp2.x86_64.rpm","freerdp-2.11.1-2.oe2203sp2.x86_64.rpm","libwinpr-2.11.1-2.oe2203sp2.x86_64.rpm","libwinpr-devel-2.11.1-2.oe2203sp2.x86_64.rpm","freerdp-devel-2.11.1-2.oe2203sp2.x86_64.rpm","freerdp-debuginfo-2.11.1-2.oe2203sp2.x86_64.rpm","freerdp-2.11.1-2.oe2203sp3.x86_64.rpm","freerdp-help-2.11.1-2.oe2203sp3.x86_64.rpm","libwinpr-devel-2.11.1-2.oe2203sp3.x86_64.rpm","libwinpr-2.11.1-2.oe2203sp3.x86_64.rpm","freerdp-devel-2.11.1-2.oe2203sp3.x86_64.rpm","freerdp-debugsource-2.11.1-2.oe2203sp3.x86_64.rpm","freerdp-debuginfo-2.11.1-2.oe2203sp3.x86_64.rpm"]}},{"package":{"ecosystem":"openEuler:22.03-LTS-SP1","name":"freerdp","purl":"pkg:rpm/openEuler/freerdp\u0026distro=openEuler-22.03-LTS-SP1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.11.1-2.oe2203sp1"}]}],"ecosystem_specific":{"aarch64":["freerdp-debugsource-2.11.1-2.oe2203sp1.aarch64.rpm","libwinpr-devel-2.11.1-2.oe2203sp1.aarch64.rpm","freerdp-devel-2.11.1-2.oe2203sp1.aarch64.rpm","libwinpr-2.11.1-2.oe2203sp1.aarch64.rpm","freerdp-2.11.1-2.oe2203sp1.aarch64.rpm","freerdp-help-2.11.1-2.oe2203sp1.aarch64.rpm","freerdp-debuginfo-2.11.1-2.oe2203sp1.aarch64.rpm"],"src":["freerdp-2.11.1-2.oe2203sp1.src.rpm"],"x86_64":["freerdp-debuginfo-2.11.1-2.oe2203sp1.x86_64.rpm","freerdp-devel-2.11.1-2.oe2203sp1.x86_64.rpm","libwinpr-2.11.1-2.oe2203sp1.x86_64.rpm","freerdp-help-2.11.1-2.oe2203sp1.x86_64.rpm","freerdp-2.11.1-2.oe2203sp1.x86_64.rpm","libwinpr-devel-2.11.1-2.oe2203sp1.x86_64.rpm","freerdp-debugsource-2.11.1-2.oe2203sp1.x86_64.rpm"]}},{"package":{"ecosystem":"openEuler:22.03-LTS-SP2","name":"freerdp","purl":"pkg:rpm/openEuler/freerdp\u0026distro=openEuler-22.03-LTS-SP2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.11.1-2.oe2203sp2"}]}],"ecosystem_specific":{"aarch64":["freerdp-debuginfo-2.11.1-2.oe2203sp2.aarch64.rpm","freerdp-help-2.11.1-2.oe2203sp2.aarch64.rpm","freerdp-2.11.1-2.oe2203sp2.aarch64.rpm","freerdp-debugsource-2.11.1-2.oe2203sp2.aarch64.rpm","libwinpr-devel-2.11.1-2.oe2203sp2.aarch64.rpm","libwinpr-2.11.1-2.oe2203sp2.aarch64.rpm","freerdp-devel-2.11.1-2.oe2203sp2.aarch64.rpm"],"src":["freerdp-2.11.1-2.oe2203sp2.src.rpm"],"x86_64":["freerdp-debugsource-2.11.1-2.oe2203sp2.x86_64.rpm","freerdp-help-2.11.1-2.oe2203sp2.x86_64.rpm","freerdp-2.11.1-2.oe2203sp2.x86_64.rpm","libwinpr-2.11.1-2.oe2203sp2.x86_64.rpm","libwinpr-devel-2.11.1-2.oe2203sp2.x86_64.rpm","freerdp-devel-2.11.1-2.oe2203sp2.x86_64.rpm","freerdp-debuginfo-2.11.1-2.oe2203sp2.x86_64.rpm"]}},{"package":{"ecosystem":"openEuler:22.03-LTS-SP3","name":"freerdp","purl":"pkg:rpm/openEuler/freerdp\u0026distro=openEuler-22.03-LTS-SP3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.11.1-2.oe2203sp3"}]}],"ecosystem_specific":{"aarch64":["libwinpr-2.11.1-2.oe2203sp3.aarch64.rpm","freerdp-help-2.11.1-2.oe2203sp3.aarch64.rpm","freerdp-devel-2.11.1-2.oe2203sp3.aarch64.rpm","libwinpr-devel-2.11.1-2.oe2203sp3.aarch64.rpm","freerdp-debugsource-2.11.1-2.oe2203sp3.aarch64.rpm","freerdp-debuginfo-2.11.1-2.oe2203sp3.aarch64.rpm","freerdp-2.11.1-2.oe2203sp3.aarch64.rpm"],"src":["freerdp-2.11.1-2.oe2203sp3.src.rpm"],"x86_64":["freerdp-2.11.1-2.oe2203sp3.x86_64.rpm","freerdp-help-2.11.1-2.oe2203sp3.x86_64.rpm","libwinpr-devel-2.11.1-2.oe2203sp3.x86_64.rpm","libwinpr-2.11.1-2.oe2203sp3.x86_64.rpm","freerdp-devel-2.11.1-2.oe2203sp3.x86_64.rpm","freerdp-debugsource-2.11.1-2.oe2203sp3.x86_64.rpm","freerdp-debuginfo-2.11.1-2.oe2203sp3.x86_64.rpm"]}}],"references":[{"type":"ADVISORY","url":"https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2024-1108"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-22211"}],"database_specific":{"severity":"Low"}}