OESA-2022-2018

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2022-2018
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2022-2018.json
JSON Data
https://api.test.osv.dev/v1/vulns/OESA-2022-2018
Upstream
Published
2022-10-26T11:04:28Z
Modified
2025-08-12T05:14:49.319013Z
Summary
freerdp security update
Details

FreeRDP is a client implementation of the Remote Desktop Protocol (RDP) that follows Microsoft's open specifications. This package provides the client applications xfreerdp and wlfreerdp.

Security Fix(es):

FreeRDP is a free remote desktop protocol library and clients. All FreeRDP based clients when using the /video command line switch might read uninitialized data, decode it as audio/video and display the result. FreeRDP based server implementations are not affected. This issue has been patched in version 2.8.1. If you cannot upgrade do not use the /video switch.(CVE-2022-39283)

FreeRDP is a free remote desktop protocol library and clients. FreeRDP based clients on unix systems using /parallel command line switch might read uninitialized data and send it to the server the client is currently connected to. FreeRDP based server implementations are not affected. Please upgrade to 2.8.1 where this issue is patched. If unable to upgrade, do not use parallel port redirection (/parallel command line switch) as a workaround.(CVE-2022-39282)

Database specific
{
    "severity": "High"
}
References

Affected packages

openEuler:20.03-LTS-SP1 / freerdp

Package

Name
freerdp
Purl
pkg:rpm/openEuler/freerdp&distro=openEuler-20.03-LTS-SP1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.8.1-1.oe1

Ecosystem specific

{
    "src": [
        "freerdp-2.8.1-1.oe1.src.rpm"
    ],
    "x86_64": [
        "freerdp-debugsource-2.8.1-1.oe1.x86_64.rpm",
        "freerdp-2.8.1-1.oe1.x86_64.rpm",
        "libwinpr-devel-2.8.1-1.oe1.x86_64.rpm",
        "freerdp-help-2.8.1-1.oe1.x86_64.rpm",
        "libwinpr-2.8.1-1.oe1.x86_64.rpm",
        "freerdp-debuginfo-2.8.1-1.oe1.x86_64.rpm",
        "freerdp-devel-2.8.1-1.oe1.x86_64.rpm"
    ],
    "aarch64": [
        "freerdp-debuginfo-2.8.1-1.oe1.aarch64.rpm",
        "freerdp-debugsource-2.8.1-1.oe1.aarch64.rpm",
        "freerdp-help-2.8.1-1.oe1.aarch64.rpm",
        "libwinpr-devel-2.8.1-1.oe1.aarch64.rpm",
        "freerdp-devel-2.8.1-1.oe1.aarch64.rpm",
        "freerdp-2.8.1-1.oe1.aarch64.rpm",
        "libwinpr-2.8.1-1.oe1.aarch64.rpm"
    ]
}

openEuler:20.03-LTS-SP3 / freerdp

Package

Name
freerdp
Purl
pkg:rpm/openEuler/freerdp&distro=openEuler-20.03-LTS-SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.8.1-1.oe1

Ecosystem specific

{
    "src": [
        "freerdp-2.8.1-1.oe1.src.rpm"
    ],
    "x86_64": [
        "freerdp-debuginfo-2.8.1-1.oe1.x86_64.rpm",
        "freerdp-help-2.8.1-1.oe1.x86_64.rpm",
        "freerdp-2.8.1-1.oe1.x86_64.rpm",
        "freerdp-debugsource-2.8.1-1.oe1.x86_64.rpm",
        "freerdp-devel-2.8.1-1.oe1.x86_64.rpm",
        "libwinpr-devel-2.8.1-1.oe1.x86_64.rpm",
        "libwinpr-2.8.1-1.oe1.x86_64.rpm"
    ],
    "aarch64": [
        "freerdp-debugsource-2.8.1-1.oe1.aarch64.rpm",
        "freerdp-help-2.8.1-1.oe1.aarch64.rpm",
        "freerdp-2.8.1-1.oe1.aarch64.rpm",
        "freerdp-devel-2.8.1-1.oe1.aarch64.rpm",
        "freerdp-debuginfo-2.8.1-1.oe1.aarch64.rpm",
        "libwinpr-devel-2.8.1-1.oe1.aarch64.rpm",
        "libwinpr-2.8.1-1.oe1.aarch64.rpm"
    ]
}

openEuler:22.03-LTS / freerdp

Package

Name
freerdp
Purl
pkg:rpm/openEuler/freerdp&distro=openEuler-22.03-LTS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.8.1-1.oe2203

Ecosystem specific

{
    "src": [
        "freerdp-2.8.1-1.oe2203.src.rpm"
    ],
    "x86_64": [
        "freerdp-debugsource-2.8.1-1.oe2203.x86_64.rpm",
        "freerdp-help-2.8.1-1.oe2203.x86_64.rpm",
        "freerdp-debuginfo-2.8.1-1.oe2203.x86_64.rpm",
        "freerdp-devel-2.8.1-1.oe2203.x86_64.rpm",
        "libwinpr-2.8.1-1.oe2203.x86_64.rpm",
        "libwinpr-devel-2.8.1-1.oe2203.x86_64.rpm",
        "freerdp-2.8.1-1.oe2203.x86_64.rpm"
    ],
    "aarch64": [
        "freerdp-2.8.1-1.oe2203.aarch64.rpm",
        "libwinpr-devel-2.8.1-1.oe2203.aarch64.rpm",
        "freerdp-devel-2.8.1-1.oe2203.aarch64.rpm",
        "libwinpr-2.8.1-1.oe2203.aarch64.rpm",
        "freerdp-help-2.8.1-1.oe2203.aarch64.rpm",
        "freerdp-debugsource-2.8.1-1.oe2203.aarch64.rpm",
        "freerdp-debuginfo-2.8.1-1.oe2203.aarch64.rpm"
    ]
}