Lucene search

K
ubuntucveUbuntu.comUB:CVE-2016-1566
HistoryFeb 02, 2017 - 12:00 a.m.

CVE-2016-1566

2017-02-0200:00:00
ubuntu.com
ubuntu.com
10

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

30.4%

Cross-site scripting (XSS) vulnerability in the file browser in Guacamole
0.9.8 and 0.9.9, when file transfer is enabled to a location shared by
multiple users, allows remote authenticated users to inject arbitrary web
script or HTML via a crafted filename. NOTE: this vulnerability was fixed
in guacamole.war on 2016-01-13, but the version number was not changed.

Notes

Author Note
seth-arnold It looks like the guacamole version numbers are useless: there are both broken versions 0.9.8 and 0.9.9 and fixed versions 0.9.8 and 0.9.9. They apparently make changes and republish with the same version number. Thus I’m being conservative and marking everything as affected.
ebarretto Affects client only

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

30.4%

Related for UB:CVE-2016-1566