PT-2023-22796 · Apache+1 · Apache Guacamole+1

Stefan Schiller

·

Published

2023-06-07

·

Updated

2025-01-29

·

CVE-2023-30575

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Apache Guacamole versions 1.5.1 and older
Description The issue arises from incorrect calculations of instruction element lengths during the Guacamole protocol handshake. This could allow an attacker to inject Guacamole instructions through specially-crafted data.
Recommendations For Apache Guacamole versions 1.5.1 and older, update to a version newer than 1.5.1 to resolve the issue.

Fix

Weakness Enumeration

Related Identifiers

ALT-PU-2023-5017
ALT-PU-2023-5018
ALT-PU-2024-16343
ALT-PU-2024-6761
ALT-PU-2024-8914
ALT-PU-2024-8918
ALT-PU-2025-2021
BIT-GUACAMOLE-2023-30575
BIT-GUACAMOLE-SERVER-2023-30575
CVE-2023-30575

Affected Products

Alt Linux
Apache Guacamole