FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, a client-side heap out-of-bounds read/write occurs in FreeRDP's bitmap cache subsystem due to an off-by-one boundary check in bitmap_cache_put. A malicious server can send a CACHE_BITMAP_ORDER (Rev1) with cacheId equal to maxCells, bypassing the guard and accessing cells[] one element past the allocated array. This vulnerability is fixed in 3.24.0.
1.1.0~git20140921.1.440916e+dfsg1-5ubuntu11.1.0~git20140921.1.440916e+dfsg1-5ubuntu1.21.1.0~git20140921.1.440916e+dfsg1-5ubuntu1.31.1.0~git20140921.1.440916e+dfsg1-5ubuntu1.41.1.0~git20140921.1.440916e+dfsg1-15ubuntu11.1.0~git20140921.1.440916e+dfsg1-15ubuntu1.18.04.11.1.0~git20140921.1.440916e+dfsg1-15ubuntu1.18.04.23.30.0+dfsg-0ubuntu0.24.04.13.14.0+dfsg-1ubuntu13.15.0+dfsg-2.13.16.0+dfsg-1ubuntu13.16.0+dfsg-23.16.0+dfsg-2ubuntu0.13.16.0+dfsg-2ubuntu0.33.16.0+dfsg-2ubuntu0.43.16.0+dfsg-2ubuntu0.5Exploitability
AV:NAC:LPR:NUI:NScope
S:UImpact
C:NI:LA:HCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H