Race Condition in Guacamole Terminal Emulator Affects Apache Software
CVE-2017-3158
8.1HIGH
Summary
The vulnerability in the terminal emulator of Apache Guacamole due to a race condition allows for overlapping writes of printed data blocks. This mismanagement can cause packet length misreads, leading to data exceeding the bounds of a statically-allocated buffer, potentially allowing for unintended behaviors and data corruption in the system.
Affected Version(s)
Apache Guacamole Apache Guacamole 0.9.5 to 0.9.10-incubating
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved