Affected versions of FreeRDP are missing input length validation in 'drive' channel. A malicious server can trick a FreeRDP based client to read out of bound data and send it back to the server. (CVE-2022-41877)
{ "section": "core" }
"https://advisories.mageia.org/MGASA-2022-0474.json"