CVE-2020-9498
published 2020-07-02CVE-2020-9498: Apache Guacamole 1.1.0 and older may mishandle pointers involved inprocessing data received via RDP static virtual channels. If a userconnects to a malicious…
PriorityP434medium6.7CVSS 3.1
AVLACHPRLUIRSUCHIHAH
EPSS
0.74%
50.3th percentile
Apache Guacamole 1.1.0 and older may mishandle pointers involved inprocessing data received via RDP static virtual channels. If a userconnects to a malicious or compromised RDP server, a series ofspecially-crafted PDUs could result in memory corruption, possiblyallowing arbitrary code to be executed with the privileges of therunning guacd process.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | guacamole | <= 1.1.0 | — |
| apache | guacamole | — | — |
| debian | debian_linux | — | — |
| debian | guacamole-server | < guacamole-server 1.3.0-1 (bullseye) | guacamole-server 1.3.0-1 (bullseye) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
CVSS provenance
nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.2MEDIUMAV:L/AC:H/Au:N/C:C/I:C/A:C
osv6.7MEDIUM
vendor_apache6.7MEDIUM
vendor_debian6.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2020-9498: guacamole-server - Apache Guacamole 1.1.0 and older may mishandle pointers involved inprocessing da...
vendor_debian·2020·CVSS 6.7
CVE-2020-9498 [MEDIUM] CVE-2020-9498: guacamole-server - Apache Guacamole 1.1.0 and older may mishandle pointers involved inprocessing da...
Apache Guacamole 1.1.0 and older may mishandle pointers involved inprocessing data received via RDP static virtual channels. If a userconnects to a malicious or compromised RDP server, a series ofspecially-crafted PDUs could result in memory corruption, possiblyallowing arbitrary code to be executed with the privileges of therunning guacd process.
Scope: local
bullseye: resolved (fixed in 1.3.0-1)
Apache
Apache guacamole: CVE-2020-9498
vendor_apache·CVSS 6.7
CVE-2020-9498 [MEDIUM] Apache guacamole: CVE-2020-9498
Apache guacamole: CVE-2020-9498
Apache Guacamole 1.1.0 and older may mishandle pointers involved in processing data received via RDP static virtual channels. If a user connects to a malicious or compromised RDP server, a series of specially-crafted PDUs could result in memory corruption, possibly allowing arbitrary code to be executed with the privileges of the running guacd process. Acknowledgements: We would like to thank Eyal Itkin (Check Point Research) for reporting this issue.
GHSA
GHSA-wrfm-qjwf-qpwj: Apache Guacamole 1
ghsa_unreviewed·2022-05-24
CVE-2020-9498 [HIGH] CWE-119 GHSA-wrfm-qjwf-qpwj: Apache Guacamole 1
Apache Guacamole 1.1.0 and older may mishandle pointers involved inprocessing data received via RDP static virtual channels. If a userconnects to a malicious or compromised RDP server, a series ofspecially-crafted PDUs could result in memory corruption, possiblyallowing arbitrary code to be executed with the privileges of therunning guacd process.
OSV
CVE-2020-9498: Apache Guacamole 1
osv·2020-07-02·CVSS 6.7
CVE-2020-9498 [MEDIUM] CVE-2020-9498: Apache Guacamole 1
Apache Guacamole 1.1.0 and older may mishandle pointers involved inprocessing data received via RDP static virtual channels. If a userconnects to a malicious or compromised RDP server, a series ofspecially-crafted PDUs could result in memory corruption, possiblyallowing arbitrary code to be executed with the privileges of therunning guacd process.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-9498 guacamole-server: Dangling pointer in RDP static virtual channel handling [epel-7]
bugzilla·2020-07-02·CVSS 6.7
CVE-2020-9498 [MEDIUM] CVE-2020-9498 guacamole-server: Dangling pointer in RDP static virtual channel handling [epel-7]
CVE-2020-9498 guacamole-server: Dangling pointer in RDP static virtual channel handling [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following templa
Bugzilla
CVE-2020-9498 guacamole-server: Dangling pointer in RDP static virtual channel handling [fedora-all]
bugzilla·2020-07-02·CVSS 6.7
CVE-2020-9498 [MEDIUM] CVE-2020-9498 guacamole-server: Dangling pointer in RDP static virtual channel handling [fedora-all]
CVE-2020-9498 guacamole-server: Dangling pointer in RDP static virtual channel handling [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects mult
Bugzilla
CVE-2020-9498 guacamole-server: Dangling pointer in RDP static virtual channel handling [epel-6]
bugzilla·2020-07-02·CVSS 6.7
CVE-2020-9498 [MEDIUM] CVE-2020-9498 guacamole-server: Dangling pointer in RDP static virtual channel handling [epel-6]
CVE-2020-9498 guacamole-server: Dangling pointer in RDP static virtual channel handling [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-6.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following templa
Bugzilla
CVE-2020-9498 guacamole-server: Dangling pointer in RDP static virtual channel handling
bugzilla·2020-07-02·CVSS 6.7
CVE-2020-9498 [MEDIUM] CVE-2020-9498 guacamole-server: Dangling pointer in RDP static virtual channel handling
CVE-2020-9498 guacamole-server: Dangling pointer in RDP static virtual channel handling
Apache Guacamole 1.1.0 and older may mishandle pointers involved in
processing data received via RDP static virtual channels. If a user
connects to a malicious or compromised RDP server, a series of
specially-crafted PDUs could result in memory corruption, possibly
allowing arbitrary code to be executed with the privileges of the
running guacd process.
Mitigation:
Users of versions of Apache Guacamole 1.1.0 and older that provide
access to untrusted RDP servers should upgrade to 1.2.0.
Discussion:
Created guacamole-server tracking bugs for this issue:
Affects: epel-6 [bug 1853387]
Affects: epel-7 [bug 1853388]
Affects: fedora-all [bug 1853386]
---
External References:
https://lists.apache.org/th
Checkpoint
Game On – Finding vulnerabilities in Valve’s “Steam Sockets”
blogs_checkpoint·2020-12-10
CVE-2020-6016 Game On – Finding vulnerabilities in Valve’s “Steam Sockets”
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
AI Research 2
Android Malware 23
Artificial Intelligence 4
ChatGPT 3
Check Point Research Publications 455
Cloud Security 1
CPRadio 44
Crypto 2
Data & Threat Intelligence 2
Data Analysis 0
Demos 22
Global Cyber Attack Reports 408
How To Guides 13
Ransomware 5
Russo-Ukrainian War 1
Security Report 1
Threat and data analysis 0
Threat Research 174
Web 3.0 Security 11
Wipers 0
## Game On – Finding vulnerabilities in Valve’s “Steam Sockets”
Research by: Eyal Itkin
## Overview
The beautiful thing about video games is that there’s something for everyone. You can p
https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44525https://lists.apache.org/thread.html/r1125f3044a0946d1e7e6f125a6170b58d413ebd4a95157e4608041c7%40%3Cannounce.apache.org%3Ehttps://lists.apache.org/thread.html/r26fb170edebff842c74aacdb1333c1338f0e19e5ec7854d72e4680fc%40%3Cannounce.apache.org%3Ehttps://lists.apache.org/thread.html/r90890afea72a9571d666820b2fe5942a0a5f86be406fa31da3dd0922%40%3Cannounce.apache.org%3Ehttps://lists.apache.org/thread.html/rff824b38ebd2fddc726b816f0e509696b83b9f78979d0cd021ca623b%40%3Cannounce.guacamole.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2020/11/msg00010.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TVV5K2X4EXSAVUUL7IJ3MUJ3ADWMVSBM/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WNS7UHBOFV6JHWH5XOEZTE3BREGRSSQ3/https://research.checkpoint.com/2020/apache-guacamole-rce/https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44525https://lists.apache.org/thread.html/r1125f3044a0946d1e7e6f125a6170b58d413ebd4a95157e4608041c7%40%3Cannounce.apache.org%3Ehttps://lists.apache.org/thread.html/r26fb170edebff842c74aacdb1333c1338f0e19e5ec7854d72e4680fc%40%3Cannounce.apache.org%3Ehttps://lists.apache.org/thread.html/r90890afea72a9571d666820b2fe5942a0a5f86be406fa31da3dd0922%40%3Cannounce.apache.org%3Ehttps://lists.apache.org/thread.html/rff824b38ebd2fddc726b816f0e509696b83b9f78979d0cd021ca623b%40%3Cannounce.guacamole.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2020/11/msg00010.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TVV5K2X4EXSAVUUL7IJ3MUJ3ADWMVSBM/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WNS7UHBOFV6JHWH5XOEZTE3BREGRSSQ3/https://research.checkpoint.com/2020/apache-guacamole-rce/
2020-07-02
Published