FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients prior to version 3.5.1 are vulnerable to out-of-bounds read. Version 3.5.1 contains a patch for the issue. No known workarounds are available.
{
"cwe_ids": [
"CWE-125"
],
"unresolved_ranges": [
{
"extracted_events": [
{
"fixed": "3.5.1"
}
],
"source": "AFFECTED_FIELD"
}
],
"cna_assigner": "GitHub_M",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/32xxx/CVE-2024-32658.json"
}[
{
"target": {
"file": "libfreerdp/codec/interleaved.c",
"function": "ExtractRunLengthMegaMega"
},
"id": "CVE-2024-32658-43372939",
"signature_type": "Function",
"deprecated": false,
"signature_version": "v1",
"digest": {
"length": 338.0,
"function_hash": "186793124219071166586429419300193128585"
},
"source": "https://github.com/freerdp/freerdp/commit/1a755d898ddc028cc818d0dd9d49d5acff4c44bf"
},
{
"target": {
"file": "libfreerdp/codec/interleaved.c"
},
"id": "CVE-2024-32658-4ebde332",
"signature_type": "Line",
"deprecated": false,
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"317051828234758370471526761738468696915",
"288613585368904614947338410449055994366",
"210452868770616871294584505579394420740",
"324422498513853662364036014075557738798",
"52745104370846841870886773199565104577",
"120966898695122949459371627640518800765",
"39688162360168337846824028198307631294",
"217918570347207610679578198123935041180"
]
},
"source": "https://github.com/freerdp/freerdp/commit/1a755d898ddc028cc818d0dd9d49d5acff4c44bf"
},
{
"target": {
"file": "libfreerdp/codec/interleaved.c",
"function": "ExtractRunLengthRegularFgBg"
},
"id": "CVE-2024-32658-65911c44",
"signature_type": "Function",
"deprecated": false,
"signature_version": "v1",
"digest": {
"length": 379.0,
"function_hash": "294261491965962563606900617485581344220"
},
"source": "https://github.com/freerdp/freerdp/commit/1a755d898ddc028cc818d0dd9d49d5acff4c44bf"
}
]
[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "38"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "39"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "40"
}
]
}
]
"2026-04-29T12:15:42Z"
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-32658.json"