CVE-2020-9497: Input Validation
Published Jul 2, 2020
·Updated
Apache Guacamole 1.1.0 and older do not properly validate datareceived from RDP servers via static virtual channels. If a userconnects to a malicious or compromised RDP server, specially-craftedPDUs could result in disclosure of information within the memory ofthe guacd process handling the connection.
Affected Software
4 affected components
Apache Guacamole<=1.1.0
Fedoraproject Fedora=32
Fedoraproject Fedora=33
Debian Debian Linux=9.0
Event History
Jul 2, 2020
CVE Published
via MITRE·12:30 PM
Data Sourced
via MITRE·12:30 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-9497.
2
What is the severity level of CVE-2020-9497?
The severity level of CVE-2020-9497 is medium with a CVSS score of 4.4.
3
How does CVE-2020-9497 affect Apache Guacamole?
CVE-2020-9497 affects Apache Guacamole version 1.1.0 and older.
4
What is the impact of CVE-2020-9497?
CVE-2020-9497 could result in disclosure of information within the memory of the guacd process handling the connection.
5
How can I fix CVE-2020-9497?
To fix CVE-2020-9497, upgrade to a version of Apache Guacamole that is not affected by the vulnerability.