CVE-2017-3158
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A race condition in Guacamole's terminal emulator in versions 0.9.5 through 0.9.10-incubating could allow writes of blocks of printed data to overlap. Such overlapping writes could cause packet data to be misread as the packet length, resulting in the remaining data being written beyond the end of a statically-allocated buffer.
Una condición de carrera en el emulador de terminal Guacamole en versiones 0.9.5 hasta la versión 0.9.10-incubating podría permitir que se solapen escrituras de bloques de datos impresos. Estas escrituras solapadas podrían provocar que los datos del paquete se lean de forma incorrecta como la longitud del paquete, lo que resultaría en que los datos que quedan se escribirían más allá del final de un búfer asignado estáticamente.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-12-05 CVE Reserved
- 2018-01-18 CVE Published
- 2024-09-16 CVE Updated
- 2024-09-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://lists.apache.org/thread.html/b218d36bfdaf655d27382daec4dcd02ec717631f4aee8b7e4300ad65%40%3Cuser.guacamole.apache.org%3E | X_refsource_misc |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apache Search vendor "Apache" | Guacamole Search vendor "Apache" for product "Guacamole" | <= 0.9.9 Search vendor "Apache" for product "Guacamole" and version " <= 0.9.9" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Guacamole Search vendor "Apache" for product "Guacamole" | 0.9.10-incubating Search vendor "Apache" for product "Guacamole" and version "0.9.10-incubating" | - |
Affected
|