cvelist/2020/9xxx/CVE-2020-9497.json

87 lines
3.7 KiB
JSON
Raw Normal View History

2020-03-01 22:01:08 +00:00
{
"data_type": "CVE",
"data_format": "MITRE",
"data_version": "4.0",
"CVE_data_meta": {
"ID": "CVE-2020-9497",
2020-07-02 13:01:28 +00:00
"ASSIGNER": "security@apache.org",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"vendor_name": "n/a",
"product": {
"product_data": [
{
"product_name": "Apache Guacamole",
"version": {
"version_data": [
{
"version_value": "Apache Guacamole 1.1.0 and older"
}
]
}
}
]
}
}
]
}
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "Information Disclosure"
}
]
}
]
},
"references": {
"reference_data": [
{
"refsource": "MISC",
"name": "https://lists.apache.org/thread.html/r65f75d3d65d1af68141f42071ebb27dda24af3e45570e593c1dbd81f%40%3Cannounce.guacamole.apache.org%3E",
"url": "https://lists.apache.org/thread.html/r65f75d3d65d1af68141f42071ebb27dda24af3e45570e593c1dbd81f%40%3Cannounce.guacamole.apache.org%3E"
2020-07-02 23:01:18 +00:00
},
{
"refsource": "MLIST",
"name": "[announce] 20200701 [SECURITY] CVE-2020-9497: Apache Guacamole: Improper input validation of RDP static virtual channels",
"url": "https://lists.apache.org/thread.html/r3f071de70ea1facd3601e0fa894e6cadc960627ee7199437b5a56f7f@%3Cannounce.apache.org%3E"
2020-07-03 23:01:17 +00:00
},
{
"refsource": "MLIST",
"name": "[guacamole-user] 20200703 Re: [SECURITY] CVE-2020-9497: Apache Guacamole: Improper input validation of RDP static virtual channels",
"url": "https://lists.apache.org/thread.html/r066543f0565e97b27c0dfe27e93e8a387b99e1e35764000224ed96e7@%3Cuser.guacamole.apache.org%3E"
},
{
"refsource": "MLIST",
"name": "[guacamole-user] 20200703 RE: [SECURITY] CVE-2020-9497: Apache Guacamole: Improper input validation of RDP static virtual channels",
"url": "https://lists.apache.org/thread.html/r181b1d5b1acb31cfa69f41b2c86ed3a2cb0b5bc09c2cbd31e9e7c847@%3Cuser.guacamole.apache.org%3E"
2020-07-06 22:01:22 +00:00
},
{
"refsource": "MISC",
"name": "https://research.checkpoint.com/2020/apache-guacamole-rce/",
"url": "https://research.checkpoint.com/2020/apache-guacamole-rce/"
2020-07-07 14:01:20 +00:00
},
{
"refsource": "CONFIRM",
"name": "https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44525",
"url": "https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44525"
2020-07-02 13:01:28 +00:00
}
]
2020-03-01 22:01:08 +00:00
},
"description": {
"description_data": [
{
"lang": "eng",
2020-07-02 13:01:28 +00:00
"value": "Apache Guacamole 1.1.0 and older do not properly validate datareceived from RDP servers via static virtual channels. If a userconnects to a malicious or compromised RDP server, specially-craftedPDUs could result in disclosure of information within the memory ofthe guacd process handling the connection."
2020-03-01 22:01:08 +00:00
}
]
}
}