{"id":"CVE-2024-32660","summary":"FreeRDP zgfx_decompress out of memory vulnerability","details":"FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.5.1, a malicious server can crash the FreeRDP client by sending invalid huge allocation size. Version 3.5.1 contains a patch for the issue. No known workarounds are available.","aliases":["GHSA-mxv6-2cw6-m3mx"],"modified":"2026-08-18T16:28:09.947711Z","published":"2024-04-23T20:03:28.529Z","related":["RLSA-2024:9092","SUSE-SU-2024:1835-1","SUSE-SU-2024:1856-1","SUSE-SU-2024:2631-1","openSUSE-SU-2024:13994-1","openSUSE-SU-2026:10123-1","openSUSE-SU-2026:20339-1"],"database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-770"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/32xxx/CVE-2024-32660.json"},"references":[{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/02/msg00016.html"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5JL476WVJSIE7SBUKVJRVA6A52V2HOLZ/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7SIS6NUNLUBOV4CPCSWKDE6T6C2W3WTR/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PX3U6YPZQ7PEJBVKSBUOLWVH7DHROHY5/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZKI4UISUXYNBPN4K6TIQKDRTIJ6CDCKJ/"},{"type":"WEB","url":"https://oss-fuzz.com/testcase-detail/5559242514825216"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/32xxx/CVE-2024-32660.json"},{"type":"ADVISORY","url":"https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-mxv6-2cw6-m3mx"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-32660"},{"type":"FIX","url":"https://github.com/FreeRDP/FreeRDP/commit/5e5d27cf310e4c10b854be7667bfb7a5d774eb47"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/freerdp/freerdp","events":[{"introduced":"0"},{"fixed":"7f6cc93c21d7f0faad6daacca06f494f29ce882c"},{"introduced":"a34fa7c49d2a39aa49ace1d7bea9656912d8c7cb"},{"fixed":"eda5c99686e15327f2f37b9cadf307e852b96adf"},{"fixed":"5e5d27cf310e4c10b854be7667bfb7a5d774eb47"}],"database_specific":{"cpe":"cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"2.11.7"},{"introduced":"3.0.0"},{"fixed":"3.5.1"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["2.11.6","3.5.0","3.4.0","3.3.0","3.2.0","2.11.5","3.1.0","2.11.4","2.11.3","3.0.0","2.11.2","2.11.1","2.11.0","2.10.0","2.9.0","2.8.1","2.8.0","2.7.0","2.6.1","2.6.0","2.5.0","2.4.1","2.3.2","2.3.1","2.3.0","2.2.0","2.1.2","2.1.1","2.1.0","2.0.0","2.0.0-rc4","2.0.0-rc3","2.0.0-rc2","2.0.0-rc1","2.0.0-rc0","2.0.0-beta1+android11","2.0.0-beta1+android10","1.2.0-beta1+android9","1.2.0-beta1+android7","1.1.0-beta+2013071101","1.1.0-beta1+ios4","1.1.0-beta1+android5","1.1.0-beta1+android4","1.1.0-beta1+ios3","1.1.0-beta1+ios2","1.1.0-beta1+android3","1.1.0-beta1+android2","1.1.0-beta1+ios1","1.1.0-beta1","1.0.1","1.0.0","1.0-beta5","1.0-beta4","1.0-beta2","1.0-beta1"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-32660.json","vanir_signatures_modified":"2026-08-18T16:28:09Z","vanir_signatures":[{"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["98830868541198649619607903992892905103","226020367808982940165966883611020331730","96209091937650497670729340190966596918","68597771232672905448747460934967876969","162044732484308792017951352105847723746","326504844733085896892666274307317621505","329690156736532059524590141505162705028","248285287506203761962394932992882009432","308160316885798277181335826747112610577","94763354898628756087767298457319091231","154844636336682889179901216075515499187","37159298558627066816814247028513832067","72487069367910799934599230940372489812","32115507658897446478508603880977138723","294609724532016567482121091644636464356","65493452997018602111792554686413876744","75632131311858889414169676597750720512","187019031097965126367024086542149720430","209425302958954328939102718034142567222","240607709657651742411609192772339157862","114855000961962168881505433138708675919","120629071858108720174159868391902029779","198379660654885751624294879516415708116","63733460343293181873015587404318800358","1935896111814404148501188144822823978","282165691124398498463447462765178984235","64406715929121521653807619913294831824","221795253243264061548387284492022111333","238417142289795488018802809977261345154","273829268001441388899797732405667081852","115631808952417382648779685705148162378","87167311721689569441319189083002267006","173993201544112695080312797135149634566","232309812463104476196058766262375004141","310754303071946827756161577055483421637","282968664398830735931325503847759908372","256216234225045447657750805627449234039","168504166255287033643095301066694785797","100394278071943054705519369221604085315","307164828607839666218062813379681665796","97039369569710529398710356863848233578","85847353457284237677959316428320400226","95631469203467702773760590192628309777","297433281680868385924423977830933093708","176260964910881623502285905975088983566","98207834689413365980693203784125073613","289350385912816381219847571713203478226","333074141710635353878506192750459148821","221872028253750179126210578171219319665","172796526059993685080506408593530779687","233079194992539652562042159116767328913","99474893695458785940087175476406851540"]},"id":"CVE-2024-32660-10b04e12","signature_type":"Line","signature_version":"v1","source":"https://github.com/freerdp/freerdp/commit/5e5d27cf310e4c10b854be7667bfb7a5d774eb47","target":{"file":"libfreerdp/codec/zgfx.c"}},{"id":"CVE-2024-32660-29ec272d","signature_type":"Function","signature_version":"v1","source":"https://github.com/freerdp/freerdp/commit/5e5d27cf310e4c10b854be7667bfb7a5d774eb47","target":{"file":"libfreerdp/codec/zgfx.c","function":"zgfx_decompress"},"deprecated":false,"digest":{"length":1537,"function_hash":"81761183092985760791528463204255662787"}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}