PT-2023-22796 · Apache+1 · Apache Guacamole+1

Stefan Schiller

·

Publicado

2023-06-07

·

Atualizado

2025-01-29

·

CVE-2023-30575

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Apache Guacamole versions 1.5.1 and older
Description The issue arises from incorrect calculations of instruction element lengths during the Guacamole protocol handshake. This could allow an attacker to inject Guacamole instructions through specially-crafted data.
Recommendations For Apache Guacamole versions 1.5.1 and older, update to a version newer than 1.5.1 to resolve the issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2023-5017
ALT-PU-2023-5018
ALT-PU-2024-16343
ALT-PU-2024-6761
ALT-PU-2024-8914
ALT-PU-2024-8918
ALT-PU-2025-2021
BIT-GUACAMOLE-2023-30575
BIT-GUACAMOLE-SERVER-2023-30575
CVE-2023-30575

Produtos afetados

Alt Linux
Apache Guacamole