CVE-2023-30575

NameCVE-2023-30575
DescriptionApache Guacamole 1.5.1 and older may incorrectly calculate the lengths of instruction elements sent during the Guacamole protocol handshake, potentially allowing an attacker to inject Guacamole instructions during the handshake through specially-crafted data.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
guacamole-client (PTS)jessie0.8.3-1.1vulnerable
stretch0.9.9+dfsg-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
guacamole-clientsourcejessie(unfixed)end-of-life
guacamole-clientsourcestretch(unfixed)end-of-life
guacamole-clientsource(unstable)(unfixed)

Search for package or bug name: Reporting problems