Debian Guacamole-Server vulnerabilities
2 known vulnerabilities affecting debian/guacamole-server.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2020-9498P4MEDIUMCVSS 6.7fixed in guacamole-server 1.3.0-1 (bullseye)2020
CVE-2020-9498 [MEDIUM] CVE-2020-9498: guacamole-server - Apache Guacamole 1.1.0 and older may mishandle pointers involved inprocessing da...
Apache Guacamole 1.1.0 and older may mishandle pointers involved inprocessing data received via RDP static virtual channels. If a userconnects to a malicious or compromised RDP server, a series ofspecially-crafted PDUs could result in memory corruption, possiblyallowing arbitrary code to be executed with the privileges of therunning guacd process.
Scope: lo
debian
CVE-2020-9497P4MEDIUMCVSS 4.4fixed in guacamole-server 1.3.0-1 (bullseye)2020
CVE-2020-9497 [MEDIUM] CVE-2020-9497: guacamole-server - Apache Guacamole 1.1.0 and older do not properly validate datareceived from RDP ...
Apache Guacamole 1.1.0 and older do not properly validate datareceived from RDP servers via static virtual channels. If a userconnects to a malicious or compromised RDP server, specially-craftedPDUs could result in disclosure of information within the memory ofthe guacd process handling the connection.
Scope: local
bullseye: resolved (fixed in 1.3.0-1)
debian