Bug 2255290 (CVE-2023-43826)

Summary: CVE-2023-43826 guacamole-server: integer overflow vulnerability
Product: [Other] Security Response Reporter: Robb Gatica <rgatica>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: redhat-bugzilla
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: guacamole 1.5.4 Doc Type: ---
Doc Text:
A flaw was reported in Apache Guacamole. In versions prior to 1.5.4, values received from VNC servers are not sufficiently validated to prevent an integer overflow condition. An attacker may use a specially-crafted payload to trigger an integer overflow, which can lead to arbitrary code execution or escalation of privileges.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2255291, 2255292    
Bug Blocks:    

Description Robb Gatica 2023-12-19 21:35:21 UTC
Apache Guacamole 1.5.3 and older do not consistently ensure that values received from a VNC server will not result in integer overflow. If a user connects to a malicious or compromised VNC server, specially-crafted data could result in memory corruption, possibly allowing arbitrary code to be executed with the privileges of the running guacd process.

Users are recommended to upgrade to version 1.5.4, which fixes this issue.

https://lists.apache.org/thread/23gzwftpfgtq97tj6ttmbclry53kmwv6

Comment 1 Robb Gatica 2023-12-19 21:35:38 UTC
Created guacamole-server tracking bugs for this issue:

Affects: epel-all [bug 2255291]
Affects: fedora-all [bug 2255292]