CVE-2012-4415
published 2012-10-01CVE-2012-4415: Stack-based buffer overflow in the guac_client_plugin_open function in libguac in Guacamole before 0.6.3 allows remote attackers to cause a denial of service…
PriorityP354high7.5CVSS 2.0
AVNACLAuNCPIPAP
EXPLOIT
EPSS
13.58%
96.0th percentile
Stack-based buffer overflow in the guac_client_plugin_open function in libguac in Guacamole before 0.6.3 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long protocol name.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | guacamole | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| guac-dev | guacamole | <= 0.6.2 | — |
| guac-dev | guacamole | — | — |
| guac-dev | guacamole | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_apache7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2prc-vxg2-86hj: Stack-based buffer overflow in the guac_client_plugin_open function in libguac in Guacamole before 0
ghsa_unreviewed·2022-05-17
CVE-2012-4415 [HIGH] CWE-119 GHSA-2prc-vxg2-86hj: Stack-based buffer overflow in the guac_client_plugin_open function in libguac in Guacamole before 0
Stack-based buffer overflow in the guac_client_plugin_open function in libguac in Guacamole before 0.6.3 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long protocol name.
OSV
CVE-2012-4415: Stack-based buffer overflow in the guac_client_plugin_open function in libguac in Guacamole before 0
osv·2012-10-01·CVSS 7.5
CVE-2012-4415 [HIGH] CVE-2012-4415: Stack-based buffer overflow in the guac_client_plugin_open function in libguac in Guacamole before 0
Stack-based buffer overflow in the guac_client_plugin_open function in libguac in Guacamole before 0.6.3 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long protocol name.
Apache
Apache guacamole: CVE-2012-4415
vendor_apache·CVSS 7.5
CVE-2012-4415 [HIGH] Apache guacamole: CVE-2012-4415
Apache guacamole: CVE-2012-4415
A stack-based buffer overflow vulnerability was discovered in the guac_client_plugin_open() function in libguac in Guacamole before 0.6.3 which could allow remote attackers to cause a denial of service (crash) or execute arbitrary code via a long protocol name. Acknowledgements: We would like to thank Timo Juhani Lindfors for reporting this issue. Copyright © 2026 The Apache Software Foundation , Licensed under the Apache License, Version 2.0 . Apache Guacamole, Guacamole, Apache, the Apache oak leaf logo, and the Apache Guacamole project logo are trademarks or registered trademarks of The Apache Software Foundation.
Affected versions: 0.6.3
No detection rules found.
Bugzilla
CVE-2012-4415 libguac: Stack-based buffer overflow by protocol handling in guac client plug-in
bugzilla·2012-09-12·CVSS 7.5
CVE-2012-4415 [HIGH] CVE-2012-4415 libguac: Stack-based buffer overflow by protocol handling in guac client plug-in
CVE-2012-4415 libguac: Stack-based buffer overflow by protocol handling in guac client plug-in
A stack based buffer overflow flaw was found in guac client plug-in protocol handling functionality of libguac, a common library used by all C components of Guacamole. A remote attacker could provide a specially-crafted protocol specification to the guac client plug-in that, when processed would lead to guac client crash (denial of service).
References:
[1] http://www.openwall.com/lists/oss-security/2012/09/11/3
[2] http://www.openwall.com/lists/oss-security/2012/09/11/7
Upstream patch:
[3] http://guac-dev.org/trac/changeset/7dcefa744b4a38825619c00ae8b47e5bae6e38c0/libguac
Discussion:
This issue affects the versions of the libguac package, as shipped with Fedora release of 16 and 17. Please
Bugzilla
CVE-2012-4415 libguac: Stack-based buffer overflow by protocol handling in guac client plug-in [fedora-all]
bugzilla·2012-09-12·CVSS 7.5
CVE-2012-4415 [HIGH] CVE-2012-4415 libguac: Stack-based buffer overflow by protocol handling in guac client plug-in [fedora-all]
CVE-2012-4415 libguac: Stack-based buffer overflow by protocol handling in guac client plug-in [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject
Bugzilla
CVE-2012-4415 libguac: Stack-based buffer overflow by protocol handling in guac client plug-in [epel-6]
bugzilla·2012-09-12·CVSS 7.5
CVE-2012-4415 [HIGH] CVE-2012-4415 libguac: Stack-based buffer overflow by protocol handling in guac client plug-in [epel-6]
CVE-2012-4415 libguac: Stack-based buffer overflow by protocol handling in guac client plug-in [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org
http://archives.neohapsis.com/archives/bugtraq/2012-09/0107.htmlhttp://guac-dev.org/trac/changeset/7dcefa744b4a38825619c00ae8b47e5bae6e38c0/libguachttp://lists.fedoraproject.org/pipermail/package-announce/2012-September/088031.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-September/088218.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-September/088272.htmlhttp://www.openwall.com/lists/oss-security/2012/09/11/3http://www.openwall.com/lists/oss-security/2012/09/11/7http://www.securityfocus.com/bid/55497https://bugzilla.redhat.com/show_bug.cgi?id=856743http://archives.neohapsis.com/archives/bugtraq/2012-09/0107.htmlhttp://guac-dev.org/trac/changeset/7dcefa744b4a38825619c00ae8b47e5bae6e38c0/libguachttp://lists.fedoraproject.org/pipermail/package-announce/2012-September/088031.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-September/088218.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-September/088272.htmlhttp://www.openwall.com/lists/oss-security/2012/09/11/3http://www.openwall.com/lists/oss-security/2012/09/11/7http://www.securityfocus.com/bid/55497https://bugzilla.redhat.com/show_bug.cgi?id=856743
2012-10-01
Published