vendor:
libguac
by:
Timo Juhani Lindfors
7,5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: libguac
Affected Version From: 0.6.0-1
Affected Version To: 0.6.0-1
Patch Exists: YES
Related CWE: CVE-2012-4415
CPE: a:guacamole:libguac
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Debian i386
2012
libguac Remote Buffer-Overflow Vulnerability
libguac is prone to a remote buffer-overflow vulnerability. Attackers can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in denial-of-service conditions. The proof-of-concept code provided allows arbitrary code execution on Debian i386 guacd 0.6.0-1 with default configuration. It uses return-to-libc to bypass non-executable stack.
Mitigation:
Upgrade to the latest version of libguac