Apache Guacamole 1.1.0 and older do not properly validate datareceived from RDP servers via static virtual channels. If a userconnects to a malicious or compromised RDP server, specially-craftedPDUs could result in disclosure of information within the memory ofthe guacd process handling the connection.
Advisories
Source ID Title
Debian DLA Debian DLA DLA-2435-1 guacamole-server security update
EUVD EUVD EUVD-2020-30303 Apache Guacamole 1.1.0 and older do not properly validate datareceived from RDP servers via static virtual channels. If a userconnects to a malicious or compromised RDP server, specially-craftedPDUs could result in disclosure of information within the memory ofthe guacd process handling the connection.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2024-08-04T10:34:38.227Z

Reserved: 2020-03-01T00:00:00

Link: CVE-2020-9497

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-07-02T13:15:10.997

Modified: 2024-11-21T05:40:46.530

Link: CVE-2020-9497

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.