Apache Guacamole 1.5.3 and older do not consistently ensure that values received from a VNC server will not result in integer overflow. If a user connects to a malicious or compromised VNC server, specially-crafted data could result in memory corruption, possibly allowing arbitrary code to be executed with the privileges of the running guacd process.
Users are recommended to upgrade to version 1.5.4, which fixes this issue.
                
            References
                    | Link | Resource | 
|---|---|
| http://www.openwall.com/lists/oss-security/2023/12/19/4 | Mailing List Third Party Advisory | 
| https://lists.apache.org/thread/23gzwftpfgtq97tj6ttmbclry53kmwv6 | Mailing List Vendor Advisory | 
| http://www.openwall.com/lists/oss-security/2023/12/19/4 | Mailing List Third Party Advisory | 
| https://lists.apache.org/thread/23gzwftpfgtq97tj6ttmbclry53kmwv6 | Mailing List Vendor Advisory | 
Configurations
                    History
                    13 Feb 2025, 17:17
| Type | Values Removed | Values Added | 
|---|---|---|
| Summary | (en) Apache Guacamole 1.5.3 and older do not consistently ensure that values received from a VNC server will not result in integer overflow. If a user connects to a malicious or compromised VNC server, specially-crafted data could result in memory corruption, possibly allowing arbitrary code to be executed with the privileges of the running guacd process. Users are recommended to upgrade to version 1.5.4, which fixes this issue. | 
Information
                Published : 2023-12-19 20:15
Updated : 2025-02-13 17:17
NVD link : CVE-2023-43826
Mitre link : CVE-2023-43826
CVE.ORG link : CVE-2023-43826
JSON object : View
Products Affected
                apache
- guacamole
CWE
                
                    
                        
                        CWE-190
                        
            Integer Overflow or Wraparound
