Bug 29870 - guacd new security issues CVE-2021-41767, CVE-2021-43999, CVE-2023-3057[56]
Summary: guacd new security issues CVE-2021-41767, CVE-2021-43999, CVE-2023-3057[56]
Status: RESOLVED OLD
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal critical
Target Milestone: ---
Assignee: Nicolas Lécureuil
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2022-01-11 23:49 CET by David Walser
Modified: 2024-01-12 09:35 CET (History)
2 users (show)

See Also:
Source RPM: guacd-1.3.0-1.mga8.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2022-01-11 23:49:37 CET
Apache has issued advisories today (January 11):
https://www.openwall.com/lists/oss-security/2022/01/11/6
https://www.openwall.com/lists/oss-security/2022/01/11/7

I'm not entirely sure whether the server, client, or both are affected.

guacd (server) is in Cauldron and Mageia 8, guacamole-client only in Mageia 7.
David Walser 2022-01-11 23:49:48 CET

Whiteboard: (none) => MGA8TOO

Comment 2 David Walser 2023-06-12 22:07:23 CEST
Apache has issued advisories on June 6:
https://www.openwall.com/lists/oss-security/2023/06/06/1
https://www.openwall.com/lists/oss-security/2023/06/06/2

The issues are fixed upstream in 1.5.2.

Summary: guacd new security issues CVE-2021-41767 and CVE-2021-43999 => guacd new security issues CVE-2021-41767, CVE-2021-43999, CVE-2023-3057[56]

Comment 3 papoteur 2023-07-01 10:34:37 CEST
We have currently guacd 1.5.1 in caudron
according to https://guacamole.apache.org/security/
Fixed in Apache Guacamole 1.4.0
    Improper validation of SAML responses (CVE-2021-43999)
    Private tunnel identifier may be included in the non-private details of active connections (CVE-2021-41767) 

Thus we still need 1.5.2

CC: (none) => yves.brungard_mageia

Comment 4 papoteur 2023-07-01 12:05:50 CEST
guacd build in 1.5.2 (cauldron testing):
guacd-1.5.2-1.mga9
lib64guac-client-rdp0-1.5.2-1.mga9
lib64guac-terminal0-1.5.2-1.mga9
guacd-client-rdp-1.5.2-1.mga9
lib64guac21-1.5.2-1.mga9
lib64guac-client-telnet0-1.5.2-1.mga9
lib64guac-client-kubernetes0-1.5.2-1.mga9
lib64guac-client-vnc0-1.5.2-1.mga9
lib64guac-client-ssh0-1.5.2-1.mga9
lib64guac-devel-1.5.2-1.mga9
Comment 5 papoteur 2023-07-02 15:29:38 CEST
Cauldron updated

Whiteboard: MGA8TOO => (none)
Version: Cauldron => 8

Comment 6 Nicolas Salguero 2024-01-12 09:35:37 CET
Mageia 8 EOL

Resolution: (none) => OLD
CC: (none) => nicolas.salguero
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.