CVE Vulnerabilities

CVE-2024-32040

Integer Underflow (Wrap or Wraparound)

Published: Apr 22, 2024 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
LOW

FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients that use a version of FreeRDP prior to 3.5.0 or 2.11.6 and have connections to servers using the NSC codec are vulnerable to integer underflow. Versions 3.5.0 and 2.11.6 patch the issue. As a workaround, do not use the NSC codec (e.g. use -nsc).

Weakness

The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.

Affected Software

Name Vendor Start Version End Version
Red Hat Enterprise Linux 9 RedHat freerdp-2:2.11.7-1.el9 *
Freerdp2 Ubuntu esm-apps/noble *
Freerdp2 Ubuntu focal *
Freerdp2 Ubuntu jammy *
Freerdp2 Ubuntu mantic *
Freerdp2 Ubuntu noble *
Freerdp2 Ubuntu oracular *
Freerdp2 Ubuntu upstream *
Freerdp3 Ubuntu devel *
Freerdp3 Ubuntu noble *
Freerdp3 Ubuntu oracular *
Freerdp3 Ubuntu upstream *

References