Package "libfreerdp-shadow-subsystem3-3"
| Name: |
libfreerdp-shadow-subsystem3-3
|
Description: |
FreeRDP Remote Desktop Protocol shadow subsystem libraries
|
| Latest version: |
3.31.0+dfsg-0ubuntu0.24.04.1 |
| Release: |
noble (24.04) |
| Level: |
updates |
| Repository: |
universe |
| Head package: |
freerdp3 |
| Homepage: |
https://www.freerdp.com/ |
Links
Download "libfreerdp-shadow-subsystem3-3"
Other versions of "libfreerdp-shadow-subsystem3-3" in Noble
Changelog
|
freerdp3 (3.5.1+dfsg1-0ubuntu1.6) noble-security; urgency=medium
* SECURITY UPDATE: heap-buffer-overflow in planar bitmap decoder
- debian/patches/CVE-2026-45700.patch: fix bounds checks
- CVE-2026-45700
* SECURITY REGRESSION: partial CVE fixes (LP: #2149819)
- debian/patches/CVE-2026-22858-fix.patch: fix incorrect
bounds check in base64_decode_char
- debian/patches/CVE-2026-23732-fix.patch: fix overflow on
32-bit systems
- debian/patches/CVE-2026-25952-fix.patch: refactor to use
xf_rail_get_window
-- Nishit Majithia <email address hidden> Fri, 12 Jun 2026 17:00:49 +0530
|
| Source diff to previous version |
| CVE-2026-45700 |
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's planar bitmap decoder has an out-of-bounds heap write whe |
| CVE-2026-22858 |
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, global-buffer-overflow was observed in FreeRDP's Base64 decoding pa |
| CVE-2026-23732 |
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, FastGlyph parsing trusts `cbData`/remaining length and neve |
| CVE-2026-25952 |
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_SetWindowMinMaxInfo` dereferences a freed `xfAppWindow` |
|
|
freerdp3 (3.5.1+dfsg1-0ubuntu1.5) noble-security; urgency=medium
* SECURITY REGRESSION: crash with realloc(): invalid next size
(LP: #2144889)
- debian/patches/CVE-2026-27951.patch: disabled, pending further
investigation.
-- Marc Deslauriers <email address hidden> Thu, 19 Mar 2026 10:23:07 -0400
|
| 2144889 |
Regression in 3.5.1+dfsg1-0ubuntu1.4: Remmina crashes with \ |
| CVE-2026-27951 |
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, the function `Stream_EnsureCapacity` can create an endless |
|
About
-
Send Feedback to @ubuntu_updates