Unrated severityNVD Advisory· Published Jun 7, 2023· Updated Oct 10, 2024
Apache Guacamole: Incorrect calculation of Guacamole protocol element lengths
CVE-2023-30575
Description
Apache Guacamole 1.5.1 and older may incorrectly calculate the lengths of instruction elements sent during the Guacamole protocol handshake, potentially allowing an attacker to inject Guacamole instructions during the handshake through specially-crafted data.
Affected products
18- osv-coords16 versionspkg:apk/chainguard/guacamole-serverpkg:apk/chainguard/guacamole-server-devpkg:apk/chainguard/guacamole-server-docpkg:apk/chainguard/libguac-client-rdppkg:apk/chainguard/libguac-client-sshpkg:apk/chainguard/libguac-client-telnetpkg:apk/chainguard/libguac-client-vncpkg:apk/wolfi/guacamole-serverpkg:apk/wolfi/guacamole-server-devpkg:apk/wolfi/guacamole-server-docpkg:apk/wolfi/libguac-client-rdppkg:apk/wolfi/libguac-client-sshpkg:apk/wolfi/libguac-client-telnetpkg:apk/wolfi/libguac-client-vncpkg:bitnami/guacamolepkg:bitnami/guacamole-server
< 0+ 15 more
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 1.5.2
- (no CPE)range: < 1.5.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- lists.apache.org/thread/tn63n2lon0h5p45oft834t1dqvvxownvmitrevendor-advisory
News mentions
0No linked articles in our index yet.