Loading HuntDB...

GHSA-3vv3-585q-wv6x

GitHub Security Advisory

Apache Guacamole Race Condition vulnerability

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

A race condition in Guacamole's terminal emulator in versions 0.9.5 through 0.9.10-incubating could allow writes of blocks of printed data to overlap. Such overlapping writes could cause packet data to be misread as the packet length, resulting in the remaining data being written beyond the end of a statically-allocated buffer.

Affected Packages

Maven org.apache.guacamole:guacamole-common
Affected versions: 0.9.5 (fixed in 0.9.11-incubating)

Related CVEs

Key Information

GHSA ID
GHSA-3vv3-585q-wv6x
Published
May 14, 2022 3:46 AM
Last Modified
November 8, 2022 11:02 PM
CVSS Score
7.5 /10
Primary Ecosystem
Maven
Primary Package
org.apache.guacamole:guacamole-common
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 28, 2025 6:37 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.