Unrated severityNVD Advisory· Published Jun 7, 2023· Updated Oct 10, 2024
Apache Guacamole: Use-after-free in handling of RDP audio input buffer
CVE-2023-30576
Description
Apache Guacamole 0.9.10 through 1.5.1 may continue to reference a freed RDP audio input buffer. Depending on timing, this may allow an attacker to execute arbitrary code with the privileges of the guacd process.
Affected products
18- osv-coords16 versionspkg:apk/chainguard/guacamole-serverpkg:apk/chainguard/guacamole-server-devpkg:apk/chainguard/guacamole-server-docpkg:apk/chainguard/libguac-client-rdppkg:apk/chainguard/libguac-client-sshpkg:apk/chainguard/libguac-client-telnetpkg:apk/chainguard/libguac-client-vncpkg:apk/wolfi/guacamole-serverpkg:apk/wolfi/guacamole-server-devpkg:apk/wolfi/guacamole-server-docpkg:apk/wolfi/libguac-client-rdppkg:apk/wolfi/libguac-client-sshpkg:apk/wolfi/libguac-client-telnetpkg:apk/wolfi/libguac-client-vncpkg:bitnami/guacamolepkg:bitnami/guacamole-server
< 0+ 15 more
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: >= 0.9.0, < 1.5.2
- (no CPE)range: >= 0.9.0, < 1.5.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- lists.apache.org/thread/vgtvxb3w7mm84hx6v8dfc0onsoz05gb6mitrevendor-advisory
News mentions
0No linked articles in our index yet.