Alerts This Week
Warning Icon 1 1,213
Alerts This Week
Warning Icon 1 1,213

Important Input Validation Vulnerability in guacamole-server for Fedora 42

fedora
Calendar Grey July 4, 2025
Dist Fedora Esm H88
Fedora 42's guacamole-server updates feature robust input validation to enhance security while offering a revamped, user-friendly interface for a better experience

Apache Guacamole 1.6.0 User interface / platform Add the ability to specify separate permissions for \u201cHistory\u201d and \u201cActive sessions\u201d tabs (GUACAMOLE-538) Sup...

Summary

Guacamole is an HTML5 remote desktop gateway.

Guacamole provides access to desktop environments using remote desktop protocols

like VNC and RDP. A centralized server acts as a tunnel and proxy, allowing

access to multiple desktops through a web browser.

No browser plugins are needed, and no client software needs to be installed. The

client requires nothing more than a web browser supporting HTML5 and AJAX.

The main web application is provided by the "guacamole-client" package.

Update Information:

Apache Guacamole 1.6.0 User interface / platform Add the ability to specify separate permissions for \u201cHistory\u201d and \u201cActive sessions\u201d tabs (GUACAMOLE-538) Support batch import of connections from CSV (GUACAMOLE-926) Add parameter token for connection name (GUACAMOLE-1177) Provide audit log for system modifications (GUACAMOLE-1224) Configurable username case sensitivity (GUACAMOLE-1239) Provide chunked file upload mechanism (GUACAMOLE-1320) Display whether user groups are disabled in group list (GUACAMOLE-1479) Support for true fullscreen mode and keyboard lock (GUACAMOLE-1525) Allow branding/customization of the section headers on the user home page (GUACAMOLE-1584) Add support for specifying VNC \u201cencodings\u201d parameter in webapp UI (GUACAMOLE-1642) Automatically clear view if session expires in background (GUACAMOLE-1744) Base64 encoding of image/binary data results in excessive syscalls that can degrade performance (GUACAMOLE-1776) Upda...

Change Log

* Tue Jun 24 2025 Robert Scheck <robert@fedoraproject.org> - 1.6.0-1 - Update to 1.6.0 (#2363860, thanks to W. Michael Petullo) - Add upstream patch for src/libguac/wol.c to fix inet_pton being called with a destination buffer size too small (GUACAMOLE-2087)

References


[ 1 ] Bug #2375882 - CVE-2024-35164 guacamole: Apache Guacamole improper input validation https://bugzilla.redhat.com/show_bug.cgi?id=2375882

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-774aa2765e' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
important
Lowest
Low
Medium
High
Critical

Name: guacamole-server
Product: Fedora 42
Version: 1.6.0
Release: 1.fc42
Summary: Server-side native components that form the Guacamole proxy

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here