CVE-2017-3158

A race condition in Guacamole's terminal emulator in versions 0.9.5 through 0.9.10-incubating could allow writes of blocks of printed data to overlap. Such overlapping writes could cause packet data to be misread as the packet length, resulting in the remaining data being written beyond the end of a statically-allocated buffer.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apache:guacamole:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:guacamole:0.9.10-incubating:*:*:*:*:*:*:*

History

07 Nov 2023, 02:44

Type Values Removed Values Added
References
  • {'url': 'https://lists.apache.org/thread.html/b218d36bfdaf655d27382daec4dcd02ec717631f4aee8b7e4300ad65@%3Cuser.guacamole.apache.org%3E', 'name': 'https://lists.apache.org/thread.html/b218d36bfdaf655d27382daec4dcd02ec717631f4aee8b7e4300ad65@%3Cuser.guacamole.apache.org%3E', 'tags': ['Vendor Advisory'], 'refsource': 'MISC'}
  • () https://lists.apache.org/thread.html/b218d36bfdaf655d27382daec4dcd02ec717631f4aee8b7e4300ad65%40%3Cuser.guacamole.apache.org%3E -

Information

Published : 2018-01-18 20:29

Updated : 2023-12-10 12:30


NVD link : CVE-2017-3158

Mitre link : CVE-2017-3158

CVE.ORG link : CVE-2017-3158


JSON object : View

Products Affected

apache

  • guacamole
CWE
CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')