In FreeRDP before version 2.1.2, there is an integer casting vulnerability in update_recv_secondary_order. All clients with +glyph-cache /relax-order-checks are affected. This is fixed in version 2.1.2.
When converting from one data type to another, such as long to integer, data can be omitted or translated in a way that produces unexpected values. If the resulting values are used in a sensitive context, then dangerous behaviors may occur.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Freerdp | Freerdp | * | 2.1.2 (excluding) |
Freerdp | Ubuntu | trusty | * |
Freerdp2 | Ubuntu | bionic | * |
Freerdp2 | Ubuntu | eoan | * |
Freerdp2 | Ubuntu | focal | * |
Freerdp2 | Ubuntu | trusty | * |