GHSA-3vv3-585q-wv6x

Suggest an improvement
Source
https://github.com/advisories/GHSA-3vv3-585q-wv6x
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-3vv3-585q-wv6x/GHSA-3vv3-585q-wv6x.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-3vv3-585q-wv6x
Aliases
Published
2022-05-14T03:46:14Z
Modified
2023-11-08T03:59:20.406623Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Apache Guacamole Race Condition vulnerability
Details

A race condition in Guacamole's terminal emulator in versions 0.9.5 through 0.9.10-incubating could allow writes of blocks of printed data to overlap. Such overlapping writes could cause packet data to be misread as the packet length, resulting in the remaining data being written beyond the end of a statically-allocated buffer.

Database specific
{
    "nvd_published_at": "2018-01-18T20:29:00Z",
    "github_reviewed_at": "2022-11-08T23:02:35Z",
    "severity": "HIGH",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-362"
    ]
}
References

Affected packages

Maven / org.apache.guacamole:guacamole-common

Package

Name
org.apache.guacamole:guacamole-common
View open source insights on deps.dev
Purl
pkg:maven/org.apache.guacamole/guacamole-common

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0.9.5
Fixed
0.9.11-incubating

Affected versions

0.*

0.9.10-incubating