Fedora Linux 8565 Published by

A guacamole-server security update has been released for Fedora 35.



SECURITY: Fedora 35 Update: guacamole-server-1.3.0-9.fc35


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2021-2c25f03d0b
2021-11-17 01:12:41.170099
--------------------------------------------------------------------------------

Name : guacamole-server
Product : Fedora 35
Version : 1.3.0
Release : 9.fc35
URL :   https://guacamole.apache.org/
Summary : Server-side native components that form the Guacamole proxy
Description :
Guacamole is an HTML5 remote desktop gateway.

Guacamole provides access to desktop environments using remote desktop protocols
like VNC and RDP. A centralized server acts as a tunnel and proxy, allowing
access to multiple desktops through a web browser.

No browser plugins are needed, and no client software needs to be installed. The
client requires nothing more than a web browser supporting HTML5 and AJAX.

The main web application is provided by the "guacamole-client" package.

--------------------------------------------------------------------------------
Update Information:

- Update to 2.4.1 containing security fixes for CVE-2021-41159 and
CVE-2021-41160. - Remmina 1.4.21 with bugfixes.
--------------------------------------------------------------------------------
ChangeLog:

* Wed Nov 10 2021 Simone Caronni - 1.3.0-9
- Rebuild for updated FreeRDP.
* Tue Sep 14 2021 Robert Scheck - 1.3.0-8
- Use -Wno-error=deprecated-declarations with OpenSSL 3.0.0
* Tue Sep 14 2021 Sahana Prasad - 1.3.0-7
- Rebuilt with OpenSSL 3.0.0
* Tue Aug 31 2021 Robert Scheck - 1.3.0-6
- Rebuilt for libwebsockets 4.2.0 (#1997842)
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2016403 - CVE-2021-41159 freerdp: improper client input validation for gateway connections allows to overwrite memory
  https://bugzilla.redhat.com/show_bug.cgi?id=2016403
[ 2 ] Bug #2016412 - CVE-2021-41160 freerdp: improper region checks in all clients allow out of bound write to memory
  https://bugzilla.redhat.com/show_bug.cgi?id=2016412
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2021-2c25f03d0b' at the command
line. For more information, refer to the dnf documentation available at
  http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
  https://fedoraproject.org/keys