Alerts This Week
Warning Icon 1 687
Alerts This Week
Warning Icon 1 687

Fedora 41: Critical Input Validation Vulnerability in guacamole-server

fedora
Calendar Grey July 4, 2025
Dist Fedora Esm H88
The latest guacamole-server update in Fedora 41 brings essential security improvements aimed at input validation flaws, urging prompt upgrades for better attack defense

Apache Guacamole 1.6.0 User interface / platform Add the ability to specify separate permissions for \u201cHistory\u201d and \u201cActive sessions\u201d tabs (GUACAMOLE-538) Sup...

Summary

Guacamole is an HTML5 remote desktop gateway.

Guacamole provides access to desktop environments using remote desktop protocols

like VNC and RDP. A centralized server acts as a tunnel and proxy, allowing

access to multiple desktops through a web browser.

No browser plugins are needed, and no client software needs to be installed. The

client requires nothing more than a web browser supporting HTML5 and AJAX.

The main web application is provided by the "guacamole-client" package.

Update Information:

Apache Guacamole 1.6.0 User interface / platform Add the ability to specify separate permissions for \u201cHistory\u201d and \u201cActive sessions\u201d tabs (GUACAMOLE-538) Support batch import of connections from CSV (GUACAMOLE-926) Add parameter token for connection name (GUACAMOLE-1177) Provide audit log for system modifications (GUACAMOLE-1224) Configurable username case sensitivity (GUACAMOLE-1239) Provide chunked file upload mechanism (GUACAMOLE-1320) Display whether user groups are disabled in group list (GUACAMOLE-1479) Support for true fullscreen mode and keyboard lock (GUACAMOLE-1525) Allow branding/customization of the section headers on the user home page (GUACAMOLE-1584) Add support for specifying VNC \u201cencodings\u201d parameter in webapp UI (GUACAMOLE-1642) Automatically clear view if session expires in background (GUACAMOLE-1744) Base64 encoding of image/binary data results in excessive syscalls that can degrade performance (GUACAMOLE-1776) Upda...

Change Log

* Tue Jun 24 2025 Robert Scheck <robert@fedoraproject.org> - 1.6.0-1 - Update to 1.6.0 (#2363860, thanks to W. Michael Petullo) - Add upstream patch for src/libguac/wol.c to fix inet_pton being called with a destination buffer size too small (GUACAMOLE-2087)

References


[ 1 ] Bug #2375882 - CVE-2024-35164 guacamole: Apache Guacamole improper input validation https://bugzilla.redhat.com/show_bug.cgi?id=2375882

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-c597fcda32' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: guacamole-server
Product: Fedora 41
Version: 1.6.0
Release: 1.fc41
Summary: Server-side native components that form the Guacamole proxy

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here