Hey there, 

I was wondering if ApacheGuacamole was susceptible to the webp exploit that was 
announced. I see in the Guacamole Server code that it is using WebP as the 
encoder, so I assume that it may be?
 
https://github.com/apache/guacamole-server/blob/master/src/libguac/encode-webp.c

Just wondering if there needs to be any testing done on this to see if it’s 
exploitable. 

Thanks! 

Caleb 

Reply via email to