From a9185f053f0c2240e239ef6ad68c82fcdb8c49f2 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Fernando=20Apestegu=C3=ADa?= Date: Fri, 24 Feb 2023 14:23:01 +0100 Subject: security/vuxml: document vulnerabilities for net/freerdp CVE-2022-39282 and CVE-2022-39283. PR: 269667 Reported by: grahamperrin@freebsd.org --- security/vuxml/vuln/2023.xml | 63 ++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 63 insertions(+) diff --git a/security/vuxml/vuln/2023.xml b/security/vuxml/vuln/2023.xml index 2ba2c6e0ac95..2a52f204707f 100644 --- a/security/vuxml/vuln/2023.xml +++ b/security/vuxml/vuln/2023.xml @@ -1,3 +1,66 @@ + + freerdp -- clients using the `/video` command line switch might read uninitialized data + + + freerdp + 2.8.1 + + + + +

MITRE reports:

+
+

+ All FreeRDP based clients when using the `/video` + command line switch might read uninitialized data, decode + it as audio/video and display the result. FreeRDP based + server implementations are not affected. +

+
+ +
+ + CVE-2022-39283 + https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-6cf9-3328-qrvh + + + 2022-10-13 + 2023-02-24 + +
+ + + freerdp -- clients using `/parallel` command line switch might read uninitialized data + + + freerdp + 2.8.1 + + + + +

MITRE reports:

+
+

+ FreeRDP based clients on unix systems using + `/parallel` command line switch might read uninitialized + data and send it to the server the client is currently + connected to. FreeRDP based server implementations are not + affected. +

+
+ +
+ + CVE-2022-39282 + https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-c45q-wcpg-mxjq + + + 2022-10-13 + 2023-02-24 + +
+ chromium -- multiple vulnerabilities -- cgit v1.2.3