GHSA-xq3v-xj62-r99vHighCVSS 7.5
FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel...
🔗 CVE IDs covered (1)
📋 Description
FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to validate maximum PDU body length before stream allocation. A malicious RDP client can send a header-only RDPEI message with a large declared body length to force excessive memory allocation on the server.