GHSA-3vv3-585q-wv6x
Dashboard / Vulnerabilities / GHSA-3vv3-585q-wv6x
Summary: Apache Guacamole Race Condition vulnerability
Details: A race condition in Guacamole's terminal emulator in versions 0.9.5 through 0.9.10-incubating could allow writes of blocks of printed data to overlap. Such overlapping writes could cause packet data to be misread as the packet length, resulting in the remaining data being written beyond the end of a statically-allocated buffer.
References: https://nvd.nist.gov/vuln/detail/CVE-2017-3158, https://lists.apache.org/thread.html/b218d36bfdaf655d27382daec4dcd02ec717631f4aee8b7e4300ad65@%3Cuser.guacamole.apache.org%3E
Affected packages
Package
Name: org.apache.guacamole:guacamole-common
Purl: pkg:maven/org.apache.guacamole/guacamole-common
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0.9.5
Fixed -0.9.11-incubating
Affected versions
0.9.10-incubating
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
