-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Wed, 06 May 2026 11:13:18 +0300
Source: freerdp3
Architecture: source
Version: 3.15.0+dfsg-2.1+deb13u3
Distribution: trixie
Urgency: medium
Maintainer: Debian Remote Maintainers <debian-remote@lists.debian.org>
Changed-By: Michael Tokarev <mjt@tls.msk.ru>
Changes:
freerdp3 (3.15.0+dfsg-2.1+deb13u3) trixie; urgency=medium
.
* security fix from 3.25.0:
.
CVE-2026-40254 off-by-one in the path traversal filter in
channels/drive/client/drive_file.c:contains_dotdot()
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-3xpj-m4hx-8vmx
clang-warnings-fix-Wjump-misses-init.patch
channels-drive-refine-bounds-checks-CVE-2026-40254.patch
Checksums-Sha1:
114f48c126dd79165a091cd6653bcf3513ce12bc 4147 freerdp3_3.15.0+dfsg-2.1+deb13u3.dsc
54b3631c05ce83b1ffae1b086091f90b8bb7c6fe 136168 freerdp3_3.15.0+dfsg-2.1+deb13u3.debian.tar.xz
1fdec132f11d183a997dc9f8910577f93a5ad63c 10566 freerdp3_3.15.0+dfsg-2.1+deb13u3_source.buildinfo
Checksums-Sha256:
cee5eb9274b26e0d579cb7710e3a18572f1b49f904d4cd0d63e5451591933ece 4147 freerdp3_3.15.0+dfsg-2.1+deb13u3.dsc
3fff1c95c64c015989283353e676cc30110ef1ef903fc2d740a4c713ad51bc68 136168 freerdp3_3.15.0+dfsg-2.1+deb13u3.debian.tar.xz
125bcdab21ed84d6c880005c00a8b671887687f14b7f6b15ce5d243cd45b7c0f 10566 freerdp3_3.15.0+dfsg-2.1+deb13u3_source.buildinfo
Files:
3925b02d6bc67c06c331cf224a0a3b6a 4147 x11 optional freerdp3_3.15.0+dfsg-2.1+deb13u3.dsc
7511f92e36b5dea5fcbedb0cce0a8c96 136168 x11 optional freerdp3_3.15.0+dfsg-2.1+deb13u3.debian.tar.xz
cd37b4583d87d6378c1c4f8fdd86c295 10566 x11 optional freerdp3_3.15.0+dfsg-2.1+deb13u3_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEZKoqtTHVaQM2a/75gqpKJDselHgFAmn6+xwACgkQgqpKJDse
lHj7TRAAy+mQ820tdVwuQxHNeh3jp7ukil8r/Rq8w+8sPCPAZh5gXApXY0/6B9AN
0E2+bPp7IJICr3NS6sTdkjiq0fl+qpRf0J/Xw0DVR0S3Td4l1Olp0KcpHjPMl3+c
6MD/LJV/sVuDbB9RcteSUGJ1+pNvF3MpbCBpPO4dpQXDX5GVbMT2JIL6vRko5j1m
KML9g8pqfVUH5GJKuWEDv4FDa6mA+ibKrQU+BDm7ZwQfZBRhyKabiK6JdLGOs0dd
T3V5MDdXB4E6B42/fDElkc1OP+zLyMDaQ6WYtdu7P4Yz11xdoHQOK+jpIZozcJfJ
N/y0m2Nhv2O1tOd+vh2QI+Ah9oJ4q8IXrymfPhDTArkXVpuOS1a1/bXe3wNGNiAp
AOYlDJx0+AFVnsT/zQEkbf2gdTobkVvXGJM9YBdoqu/icRmfa3T9iO5wxGf/ZmKu
yimLZev7rwWiq6mSwKtNMtqjxMcPwAXoivwdMlWBq0Yv+aARnd7ulrj/l6iQQ+i3
uNUN8QLPhPqmtr0ySp30wm2epYqg4wsMeQriaN4fALEoGgcphWTCzY+Yo+1CCJ/s
pCQfbJIKmEvzNz8OCvQX/O86c+0f1FZvf+lHgKsUeoWxk/ZGTl4K+llPd0IWxMKS
w6jJPlKKALPJlxoHk+9CvENaEwbrIt3JmfJOLXTCSi/c2eF9Kt4=
=g4b6
-----END PGP SIGNATURE-----