SUSE has issued an advisory on November 15: https://lists.suse.com/pipermail/sle-security-updates/2022-November/012920.html The issues are fixed upstream in 2.8.1: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-c45q-wcpg-mxjq https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-6cf9-3328-qrvh https://github.com/FreeRDP/FreeRDP/releases/tag/2.8.1
Status comment: (none) => Fixed upstream in 2.8.1
Equivalent openSUSE advisory: https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/HJA3DXXYKZSQPM7VF5GX343WBGCGAPAH/
Assigning to you, DavidG, seeing you have already put version: 2.8.1 into Cauldron, and are even the registered maintainer. Glad to see you.
Assignee: bugsquad => geiger.david68210
OK, version: 2.8.1 is in Cauldron. Re-assigning this globally, may have erred initially.
Assignee: geiger.david68210 => pkg-bugs
Suggested advisory: ======================== The updated packages fix security vulnerabilities: FreeRDP based clients on unix systems using `/parallel` command line switch might read uninitialized data and send it to the server the client is currently connected to. (CVE-2022-39282) All FreeRDP based clients when using the `/video` command line switch might read uninitialized data, decode it as audio/video and display the result. (CVE-2022-39283) References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-39282 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-39283 https://lists.suse.com/pipermail/sle-security-updates/2022-November/012920.html https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-c45q-wcpg-mxjq https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-6cf9-3328-qrvh https://github.com/FreeRDP/FreeRDP/releases/tag/2.8.1 https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/HJA3DXXYKZSQPM7VF5GX343WBGCGAPAH/ ======================== Updated packages in core/updates_testing: ======================== freerdp-2.2.0-1.3.mga8 lib(64)freerdp2-2.2.0-1.3.mga8 lib(64)freerdp-devel-2.2.0-1.3.mga8 from SRPM: freerdp-2.2.0-1.3.mga8.src.rpm
Assignee: pkg-bugs => qa-bugsCC: (none) => nicolas.salgueroCVE: (none) => CVE-2022-39282, CVE-2022-39283Status: NEW => ASSIGNEDStatus comment: Fixed upstream in 2.8.1 => (none)
MGA8-64 MATE on Acer Aspire 5253 No installation issues Followed example from bug 30392 Comment 8 with the remark that the correct syntax seems to be xfreerdp /v:<server>:3984 /u:user> /p:<munged> thus / i.s.o. - Had the same effect, view OK, no mouse control. so OK as then.
Whiteboard: (none) => MGA8-64-OKCC: (none) => herman.viaene
Validating. Advisory in Comment 4.
CC: (none) => andrewsfarm, sysadmin-bugsKeywords: (none) => validated_update
CC: (none) => davidwhodginsKeywords: (none) => advisory
An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2022-0437.html
Resolution: (none) => FIXEDStatus: ASSIGNED => RESOLVED