PT-2020-20701 · Apache · Apache Guacamole
Eyal Itkin
·
Published
2020-07-02
·
Updated
2024-03-06
·
CVE-2020-9497
4.4
Medium
Base vector | Vector | AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Apache Guacamole versions 1.1.0 and older
Description:
The issue arises from improper validation of data received from RDP servers via static virtual channels. If a user connects to a malicious or compromised RDP server, specially-crafted PDUs could result in disclosure of information within the memory of the guacd process handling the connection.
Recommendations:
For Apache Guacamole versions 1.1.0 and older, consider updating to a version that properly validates data from RDP servers to prevent potential information disclosure. As a temporary workaround, restrict connections to trusted RDP servers to minimize the risk of exploitation.
Fix
RCE
Weakness Enumeration
Related Identifiers
Affected Products
References · 43
- https://osv.dev/vulnerability/MGASA-2021-0272 · Vendor Advisory
- https://bdu.fstec.ru/vul/2021-02004 · Security Note
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/WNS7UHBOFV6JHWH5XOEZTE3BREGRSSQ3 · Vendor Advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/32RWZPQ7FRP73BVKOQK27XV6TX47TT3R · Vendor Advisory
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9498 · Security Note
- https://ubuntu.com/security/CVE-2020-9497 · Vendor Advisory
- https://osv.dev/vulnerability/CVE-2020-9497 · Vendor Advisory
- https://cve.org/CVERecord?id=CVE-2020-9497 · Security Note
- https://osv.dev/vulnerability/UBUNTU-CVE-2020-9497 · Vendor Advisory
- https://osv.dev/vulnerability/BIT-guacamole-2020-9497 · Vendor Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TVV5K2X4EXSAVUUL7IJ3MUJ3ADWMVSBM · Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-9497 · Security Note
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9497 · Security Note
- https://osv.dev/vulnerability/BIT-guacamole-server-2020-9497 · Vendor Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WNS7UHBOFV6JHWH5XOEZTE3BREGRSSQ3 · Vendor Advisory