First published: Wed Jun 07 2023(Updated: )
Apache Guacamole 0.9.10 through 1.5.1 may continue to reference a freed RDP audio input buffer. Depending on timing, this may allow an attacker to execute arbitrary code with the privileges of the guacd process.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Guacamole | >=0.9.0<1.5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-30576 is high.
The vulnerability ID for Apache Guacamole 0.9.10 through 1.5.1 is CVE-2023-30576.
The affected software for CVE-2023-30576 is Apache Guacamole versions 0.9.10 through 1.5.1.
An attacker can potentially execute arbitrary code with the privileges of the guacd process by exploiting CVE-2023-30576.
Yes, the fix for CVE-2023-30576 is available in Apache Guacamole version 1.5.2.