CVE-2023-30576: Apache Guacamole: Use-after-free in handling of RDP audio input buffer
Published Jun 7, 2023
·Updated
Apache Guacamole 0.9.10 through 1.5.1 may continue to reference a freed RDP audio input buffer. Depending on timing, this may allow an attacker to execute arbitrary code with the privileges of the guacd process.
Affected Software
1 affected component
Apache Guacamole>=0.9.0<1.5.2
Event History
Jun 7, 2023
CVE Published
via MITRE·08:06 AM
Data Sourced
via MITRE·08:06 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-30576?
The severity of CVE-2023-30576 is high.
2
What is the vulnerability ID for Apache Guacamole 0.9.10 through 1.5.1?
The vulnerability ID for Apache Guacamole 0.9.10 through 1.5.1 is CVE-2023-30576.
3
What is the affected software for CVE-2023-30576?
The affected software for CVE-2023-30576 is Apache Guacamole versions 0.9.10 through 1.5.1.
4
How can an attacker exploit CVE-2023-30576?
An attacker can potentially execute arbitrary code with the privileges of the guacd process by exploiting CVE-2023-30576.
5
Is there a fix available for CVE-2023-30576?
Yes, the fix for CVE-2023-30576 is available in Apache Guacamole version 1.5.2.