vulnerability
Debian: CVE-2020-9497: guacamole-server -- security update
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
1 | (AV:L/AC:H/Au:N/C:P/I:N/A:N) | Jul 2, 2020 | Nov 9, 2020 | Nov 9, 2020 |
Severity
1
CVSS
(AV:L/AC:H/Au:N/C:P/I:N/A:N)
Published
Jul 2, 2020
Added
Nov 9, 2020
Modified
Nov 9, 2020
Description
Apache Guacamole 1.1.0 and older do not properly validate datareceived from RDP servers via static virtual channels. If a userconnects to a malicious or compromised RDP server, specially-craftedPDUs could result in disclosure of information within the memory ofthe guacd process handling the connection.
Solution
debian-upgrade-guacamole-server

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.