SUSE-SU-2023:4893-1

    Dashboard / Vulnerabilities / SUSE-SU-2023:4893-1

    SUSE-SU-2023:4893-1

    Published: 18 Dec 2023Last Modified: 4 Feb 2026

    Summary: Security update for freerdp

    Details: This update for freerdp fixes the following issues: - CVE-2023-39350: Fixed incorrect offset calculation leading to DoS (bsc#1214856). - CVE-2023-39351: Fixed Null Pointer Dereference leading DoS in RemoteFX (bsc#1214857). - CVE-2023-39352: Fixed Invalid offset validation leading to Out Of Bound Write (bsc#1214858). - CVE-2023-39353: Fixed Missing offset validation leading to Out Of Bound Read (bsc#1214859). - CVE-2023-39354: Fixed Out-Of-Bounds Read in nsc_rle_decompress_data (bsc#1214860). - CVE-2023-39356: Fixed Missing offset validation leading to Out-of-Bounds Read in gdi_multi_opaque_rect (bsc#1214862). - CVE-2023-40181: Fixed Integer-Underflow leading to Out-Of-Bound Read in zgfx_decompress_segment (bsc#1214863). - CVE-2023-40186: Fixed IntegerOverflow leading to Out-Of-Bound Write Vulnerability in gdi_CreateSurface (bsc#1214864). - CVE-2023-40188: Fixed Out-Of-Bounds Read in general_LumaToYUV444 (bsc#1214866). - CVE-2023-40567: Fixed Out-Of-Bounds Write in clear_decompress_bands_data (bsc#1214867). - CVE-2023-40569: Fixed Out-Of-Bounds Write in progressive_decompress (bsc#1214868). - CVE-2023-40574: Fixed Out-Of-Bounds Write in general_YUV444ToRGB_8u_P3AC4R_BGRX (bsc#1214869). - CVE-2023-40575: Fixed Out-Of-Bounds Read in general_YUV444ToRGB_8u_P3AC4R_BGRX (bsc#1214870). - CVE-2023-40576: Fixed Out-Of-Bounds Read in RleDecompress (bsc#1214871). - CVE-2023-40589: Fixed Global-Buffer-Overflow in ncrush_decompress (bsc#1214872).

    Affected packages

    Package

    Name: freerdp

    Purl: pkg:rpm/suse/freerdp&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP4

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -2.4.0-150400.3.23.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    SUSE-SU-2023:4893-1 | CVE-DB