CVE-2017-3158: Buffer overflow in SSH/telnet terminal emulator

Versions affected:
Apache Guacamole prior to 0.9.11-incubating

Description:
A race condition in Guacamole's terminal emulator could allow writes of
blocks of printed data to overlap. Such overlapping writes could cause
packet data to be misread as the packet length, resulting in the remaining
data being written beyond the end of a statically-allocated buffer.

Mitigation:
Users of Apache Guacamole 0.9.10-incubating or older should upgrade to at
least 0.9.11-incubating.

Credit:
We would like to thank Hariprasad Ng for reporting this issue.

Reply via email to