#VU80397 Out-of-bounds read in FreeRDP - CVE-2023-39354
Published: September 4, 2023
FreeRDP
FreeRDP
Description
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary condition in nsc_rle_decompress_data() function in libfreerdp/codec/nsc.c. A remote user can send specially crafted data to the application, trigger an out-of-bounds read error and perform a denial of service (DoS) attack.