SUSE-SU-2023:4893-1
Dashboard / Vulnerabilities / SUSE-SU-2023:4893-1
SUSE-SU-2023:4893-1
Summary: Security update for freerdp
Details: This update for freerdp fixes the following issues: - CVE-2023-39350: Fixed incorrect offset calculation leading to DoS (bsc#1214856). - CVE-2023-39351: Fixed Null Pointer Dereference leading DoS in RemoteFX (bsc#1214857). - CVE-2023-39352: Fixed Invalid offset validation leading to Out Of Bound Write (bsc#1214858). - CVE-2023-39353: Fixed Missing offset validation leading to Out Of Bound Read (bsc#1214859). - CVE-2023-39354: Fixed Out-Of-Bounds Read in nsc_rle_decompress_data (bsc#1214860). - CVE-2023-39356: Fixed Missing offset validation leading to Out-of-Bounds Read in gdi_multi_opaque_rect (bsc#1214862). - CVE-2023-40181: Fixed Integer-Underflow leading to Out-Of-Bound Read in zgfx_decompress_segment (bsc#1214863). - CVE-2023-40186: Fixed IntegerOverflow leading to Out-Of-Bound Write Vulnerability in gdi_CreateSurface (bsc#1214864). - CVE-2023-40188: Fixed Out-Of-Bounds Read in general_LumaToYUV444 (bsc#1214866). - CVE-2023-40567: Fixed Out-Of-Bounds Write in clear_decompress_bands_data (bsc#1214867). - CVE-2023-40569: Fixed Out-Of-Bounds Write in progressive_decompress (bsc#1214868). - CVE-2023-40574: Fixed Out-Of-Bounds Write in general_YUV444ToRGB_8u_P3AC4R_BGRX (bsc#1214869). - CVE-2023-40575: Fixed Out-Of-Bounds Read in general_YUV444ToRGB_8u_P3AC4R_BGRX (bsc#1214870). - CVE-2023-40576: Fixed Out-Of-Bounds Read in RleDecompress (bsc#1214871). - CVE-2023-40589: Fixed Global-Buffer-Overflow in ncrush_decompress (bsc#1214872).
References: https://www.suse.com/support/update/announcement/2023/suse-su-20234893-1/, https://bugzilla.suse.com/1214856, https://bugzilla.suse.com/1214857, https://bugzilla.suse.com/1214858, https://bugzilla.suse.com/1214859, https://bugzilla.suse.com/1214860, https://bugzilla.suse.com/1214862, https://bugzilla.suse.com/1214863, https://bugzilla.suse.com/1214864, https://bugzilla.suse.com/1214866, https://bugzilla.suse.com/1214867, https://bugzilla.suse.com/1214868, https://bugzilla.suse.com/1214869, https://bugzilla.suse.com/1214870, https://bugzilla.suse.com/1214871, https://bugzilla.suse.com/1214872, https://www.suse.com/security/cve/CVE-2023-39350, https://www.suse.com/security/cve/CVE-2023-39351, https://www.suse.com/security/cve/CVE-2023-39352, https://www.suse.com/security/cve/CVE-2023-39353, https://www.suse.com/security/cve/CVE-2023-39354, https://www.suse.com/security/cve/CVE-2023-39356, https://www.suse.com/security/cve/CVE-2023-40181, https://www.suse.com/security/cve/CVE-2023-40186, https://www.suse.com/security/cve/CVE-2023-40188, https://www.suse.com/security/cve/CVE-2023-40567, https://www.suse.com/security/cve/CVE-2023-40569, https://www.suse.com/security/cve/CVE-2023-40574, https://www.suse.com/security/cve/CVE-2023-40575, https://www.suse.com/security/cve/CVE-2023-40576, https://www.suse.com/security/cve/CVE-2023-40589
Affected packages
Package
Name: freerdp
Purl: pkg:rpm/suse/freerdp&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP4
Affected ranges
Type: ECOSYSTEM
Events:
