A Remote Desktop Protocol Implementation
Security Fix(es):
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. All FreeRDP clients prior to version 2.4.1 using gateway connections fail to validate input data. A malicious gateway might allow client memory to be written out of bounds. This issue has been resolved in version 2.4.1. If you are unable to update then use /gt:http rather than /gt:rdp connections if possible or use a direct connection without a gateway.(CVE-2021-41159)
{
"severity": "Critical"
}{
"aarch64": [
"freerdp-2.4.1-1.oe1.aarch64.rpm",
"freerdp-debuginfo-2.4.1-1.oe1.aarch64.rpm",
"freerdp-debugsource-2.4.1-1.oe1.aarch64.rpm",
"freerdp-devel-2.4.1-1.oe1.aarch64.rpm",
"freerdp-help-2.4.1-1.oe1.aarch64.rpm",
"libwinpr-2.4.1-1.oe1.aarch64.rpm",
"libwinpr-devel-2.4.1-1.oe1.aarch64.rpm"
],
"src": [
"freerdp-2.4.1-1.oe1.src.rpm"
],
"x86_64": [
"freerdp-2.4.1-1.oe1.x86_64.rpm",
"freerdp-debuginfo-2.4.1-1.oe1.x86_64.rpm",
"freerdp-debugsource-2.4.1-1.oe1.x86_64.rpm",
"freerdp-devel-2.4.1-1.oe1.x86_64.rpm",
"freerdp-help-2.4.1-1.oe1.x86_64.rpm",
"libwinpr-2.4.1-1.oe1.x86_64.rpm",
"libwinpr-devel-2.4.1-1.oe1.x86_64.rpm"
]
}
{
"aarch64": [
"freerdp-2.4.1-1.oe1.aarch64.rpm",
"freerdp-debuginfo-2.4.1-1.oe1.aarch64.rpm",
"freerdp-debugsource-2.4.1-1.oe1.aarch64.rpm",
"freerdp-devel-2.4.1-1.oe1.aarch64.rpm",
"freerdp-help-2.4.1-1.oe1.aarch64.rpm",
"libwinpr-2.4.1-1.oe1.aarch64.rpm",
"libwinpr-devel-2.4.1-1.oe1.aarch64.rpm"
],
"src": [
"freerdp-2.4.1-1.oe1.src.rpm"
],
"x86_64": [
"freerdp-2.4.1-1.oe1.x86_64.rpm",
"freerdp-debuginfo-2.4.1-1.oe1.x86_64.rpm",
"freerdp-debugsource-2.4.1-1.oe1.x86_64.rpm",
"freerdp-devel-2.4.1-1.oe1.x86_64.rpm",
"freerdp-help-2.4.1-1.oe1.x86_64.rpm",
"libwinpr-2.4.1-1.oe1.x86_64.rpm",
"libwinpr-devel-2.4.1-1.oe1.x86_64.rpm"
]
}