Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wrfm-qjwf-qpwj

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Apache Guacamole 1.1.0 and older may mishandle pointers involved inprocessing data received via RDP static virtual channels. If a userconnects to a malicious or compromised RDP server, a series ofspecially-crafted PDUs could result in memory corruption, possiblyallowing arbitrary code to be executed with the privileges of therunning guacd process.

Apache Guacamole 1.1.0 and older may mishandle pointers involved inprocessing data received via RDP static virtual channels. If a userconnects to a malicious or compromised RDP server, a series ofspecially-crafted PDUs could result in memory corruption, possiblyallowing arbitrary code to be executed with the privileges of therunning guacd process.

EPSS

Процентиль: 29%
0.00107
Низкий

Дефекты

CWE-119

Связанные уязвимости

CVSS3: 6.7
ubuntu
больше 5 лет назад

Apache Guacamole 1.1.0 and older may mishandle pointers involved inprocessing data received via RDP static virtual channels. If a userconnects to a malicious or compromised RDP server, a series ofspecially-crafted PDUs could result in memory corruption, possiblyallowing arbitrary code to be executed with the privileges of therunning guacd process.

CVSS3: 6.7
nvd
больше 5 лет назад

Apache Guacamole 1.1.0 and older may mishandle pointers involved inprocessing data received via RDP static virtual channels. If a userconnects to a malicious or compromised RDP server, a series ofspecially-crafted PDUs could result in memory corruption, possiblyallowing arbitrary code to be executed with the privileges of therunning guacd process.

CVSS3: 6.7
debian
больше 5 лет назад

Apache Guacamole 1.1.0 and older may mishandle pointers involved inpro ...

CVSS3: 6.7
fstec
больше 5 лет назад

Уязвимость программного обеспечения для удаленного администрирования клиентских машин Apache Guacamole, связанная с выходом операции за границы буфера в памяти, позволяющая нарушителю повысить свои привилегии и выполнить произвольный код

EPSS

Процентиль: 29%
0.00107
Низкий

Дефекты

CWE-119