High severity7.5NVD Advisory· Published Dec 19, 2023· Updated Jun 17, 2026
CVE-2023-43826
CVE-2023-43826
Description
Apache Guacamole 1.5.3 and older do not consistently ensure that values received from a VNC server will not result in integer overflow. If a user connects to a malicious or compromised VNC server, specially-crafted data could result in memory corruption, possibly allowing arbitrary code to be executed with the privileges of the running guacd process.
Users are recommended to upgrade to version 1.5.4, which fixes this issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4<=1.5.3+ 1 more
- (no CPE)range: <=1.5.3
- (no CPE)range: 0
- osv-coords2 versions
< 1.5.3+ 1 more
- (no CPE)range: < 1.5.3
- (no CPE)range: < 1.5.3
Patches
Vulnerability mechanics
References
2- www.openwall.com/lists/oss-security/2023/12/19/4nvdMailing ListThird Party Advisory
- lists.apache.org/thread/23gzwftpfgtq97tj6ttmbclry53kmwv6nvdMailing ListVendor Advisory
News mentions
0No linked articles in our index yet.