Race condition in the worker_update_monitors_config function in SPICE 0.12.4 allows a remote authenticated guest user to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) or possibly execute arbitrary code on the host via unspecified vectors.
CVSS Details
- CVSS 3.1 Base Score: 7
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade spice | Aug 30, 2017 | Sep 8, 2015 |
| Centos_linux | — | Upgrade spice-server-develUpgrade spice-server | Dec 1, 2016 | Sep 8, 2015 |
| Debian | — | Upgrade spice | Jul 30, 2024 | Sep 8, 2015 |
| Oracle_linux | — | Upgrade spice-server-develUpgrade spice-server | Oct 16, 2024 | Sep 8, 2015 |
| Suse | — | Upgrade libspice-server1Upgrade libspice-server-devel | Dec 18, 2015 | Sep 8, 2015 |
| Ubuntu | — | Upgrade libspice-server1 | Nov 8, 2024 | Sep 8, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub