Related Vulnerabilities: CVE-2021-37595  

In FreeRDP before 2.4.0 on Windows, wf_cliprdr_server_file_contents_request in client/Windows/wf_cliprdr.c has missing input checks for a FILECONTENTS_RANGE File Contents Request PDU.

Severity Medium

Remote Yes

Type Insufficient validation

Description

In FreeRDP before 2.4.0 on Windows, wf_cliprdr_server_file_contents_request in client/Windows/wf_cliprdr.c has missing input checks for a FILECONTENTS_RANGE File Contents Request PDU.

AVG-2227 freerdp 2:2.3.2-1 Medium Not affected

https://github.com/FreeRDP/FreeRDP/pull/7185
https://github.com/FreeRDP/FreeRDP/commit/7019140a22615be202f8e0710115f2b05ff64d05