CVE-2017-3158

Description

A race condition in Guacamoles terminal emulator in versions 0.9.5 through 0.9.10-incubating could allow writes of blocks of printed data to overlap. Such overlapping writes could cause packet data to be misread as the packet length, resulting in the remaining data being written beyond the end of a statically-allocated buffer.

Risk Information

Base Score
8.1
MODERATE
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.687

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2017-3158 are fixed in Apache-guacamole-common 0.9.11Windows
Vulnerabilities CVE-2017-3158 are fixed in Apache-guacamole-common for Linux 0.9.11Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234