REDHAT-BUG-856743: Buffer Overflow
A stack based buffer overflow flaw was found in guac client plug-in protocol handling functionality of libguac, a common library used by all C components of Guacamole. A remote attacker could provide a specially-crafted protocol specification to the guac client plug-in that, when processed would lead to guac client crash (denial of service).
References: [1] http://www.openwall.com/lists/oss-security/2012/09/11/3 [2] http://www.openwall.com/lists/oss-security/2012/09/11/7
Upstream patch: [3] http://guac-dev.org/trac/changeset/7dcefa744b4a38825619c00ae8b47e5bae6e38c0/libguac
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-856743?
The severity of REDHAT-BUG-856743 is classified as low.
What type of vulnerability is REDHAT-BUG-856743?
REDHAT-BUG-856743 is identified as a buffer overflow vulnerability.
How do I fix REDHAT-BUG-856743?
To fix REDHAT-BUG-856743, update to the latest version of Apache libguac that addresses this vulnerability.
What components are affected by REDHAT-BUG-856743?
The guac client plug-in protocol handling functionality of libguac is affected by REDHAT-BUG-856743.
Can REDHAT-BUG-856743 be exploited remotely?
Yes, a remote attacker could exploit REDHAT-BUG-856743 by providing a specially-crafted protocol specification.