CVE-2024-32459: freerdp: out-of-bounds read in ncrush_decompress

Severity: Critical

CVSS Score: 9.8

FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients and servers that use a version of FreeRDP prior to 3.5.0 or 2.11.6 are vulnerable to out-of-bounds read. Versions 3.5.0 and 2.11.6 patch the issue. No known workarounds are available.