🛡️ SUSE-SU-2023:4611-1 — freerdp (CVE-2023-39350 +14 more)
Description
Security update for freerdp
This update for freerdp fixes the following issues:
- CVE-2023-39350: Fixed incorrect offset calculation leading to DoS (bsc#1214856).
- CVE-2023-39351: Fixed Null Pointer Dereference leading DoS in RemoteFX (bsc#1214857).
- CVE-2023-39352: Fixed Invalid offset validation leading to Out Of Bound Write (bsc#1214858).
- CVE-2023-39353: Fixed Missing offset validation leading to Out Of Bound Read (bsc#1214859).
- CVE-2023-39354: Fixed Out-Of-Bounds Read in nsc_rle_decompress_data (bsc#1214860).
- CVE-2023-39356: Fixed Missing offset validation leading to Out-of-Bounds Read in gdi_multi_opaque_rect (bsc#1214862).
- CVE-2023-40181: Fixed Integer-Underflow leading to Out-Of-Bound Read in zgfx_decompress_segment (bsc#1214863).
- CVE-2023-40186: Fixed IntegerOverflow leading to Out-Of-Bound Write Vulnerability in gdi_CreateSurface (bsc#1214864).
- CVE-2023-40188: Fixed Out-Of-Bounds Read in general_LumaToYUV444 (bsc#1214866).
- CVE-2023-40567: Fixed Out-Of-Bounds Write in clear_decompress_bands_data (bsc#1214867).
- CVE-2023-40569: Fixed Out-Of-Bounds Write in progressive_decompress (bsc#1214868).
- CVE-2023-40574: Fixed Out-Of-Bounds Write in general_YUV444ToRGB_8u_P3AC4R_BGRX (bsc#1214869).
- CVE-2023-40575: Fixed Out-Of-Bounds Read in general_YUV444ToRGB_8u_P3AC4R_BGRX (bsc#1214870).
- CVE-2023-40576: Fixed Out-Of-Bounds Read in RleDecompress (bsc#1214871).
- CVE-2023-40589: Fixed Global-Buffer-Overflow in ncrush_decompress (bsc#1214872).
Affected software
SUSE-SU-2023:4611-1 is recorded against 1 package.
- freerdp (fixed in 2.1.2-12.38.1)
Timeline and source
Published on 29 November 2023 and last revised on 4 February 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
www.suse.com (Advisory)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| freerdp | — | 2.1.2-12.38.1 |
References
Similar Threats
- Unknown ALSA-2026:50747
- Unknown ALSA-2026:38501
- Unknown ALSA-2026:37207
- Unknown ALSA-2026:36203
- Unknown ALSA-2026:19358
Free Vulnerability Check
Is your site affected by SUSE-SU-2023:4611-1?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-SU-2023:4611-1 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.