Skip to finding
important · Privilege

FreeRDP can leave active smart-card and generated private keys readable by another local account.

Affects

FreeRDP, an RDP client/server implementation and toolkit on Linux and other Unix-like systems.

Under a common 022 umask, private-key files could inherit permissions broad enough for another user on a shared Unix host to read an active temporary copy or traversable output file.

Detail and 3 sources
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Tuesday, September 29, 2026