Import fix for CVE-2022-24882 - Server side NTLM does not properly check parameters.

This commit is contained in:
Tobias Frost 2023-10-28 19:28:36 +02:00
parent 14442af9ac
commit a8d9578fb9
3 changed files with 3444 additions and 1 deletions

5
debian/changelog vendored
View File

@ -3,7 +3,10 @@ freerdp2 (2.3.0+dfsg1-2+deb10u4) UNRELEASED; urgency=medium
* Non-maintainer upload by the LTS Security Team.
* Import fix for CVE-2021-41160 - Improper region checks in all clients
allow out of bound write to memory (Closes: #1001062)
* Previous upload: fix typo in CVE list. It was CVE 2023-40567 not CVE 2023-39357
* Import fix for CVE-2022-24882 - Server side NTLM does not properly check
parameters.
* Previous upload: fix typo in CVE list. It was CVE 2023-40567 not CVE
2023-39357.
-- Tobias Frost <tobi@debian.org> Sat, 28 Oct 2023 18:12:57 +0200

3439
debian/patches/0051-CVE-2022-24882.patch vendored Normal file

File diff suppressed because it is too large Load Diff

View File

@ -40,3 +40,4 @@
0048-CVE-2023-40569.patch
0049-CVE-2023-40589.patch
0050-CVE-2021-41160.patch
0051-CVE-2022-24882.patch