SPICE allows local guest OS users to read from or write to arbitrary host memory locations via crafted primary surface parameters, a similar issue to CVE-2015-5261.
CVSS Details
- CVSS 3.1 Base Score: 7.1
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade spice-serverUpgrade spice-server-devel | Jul 22, 2016 | Jun 7, 2016 |
| Debian | — | Upgrade spice | Jun 6, 2016 | Jun 6, 2016 |
| Gentoo Linux | — | Upgrade app-emulation/spice. | Oct 30, 2017 | Jun 9, 2016 |
| Oracle_linux | — | Upgrade spice-server-develUpgrade spice-server | Jun 6, 2016 | Jun 6, 2016 |
| Redhat_linux | — | Upgrade spice-server-debuginfoUpgrade spice-serverUpgrade spice-server-develUpgrade spice-debuginfo | Jul 29, 2016 | Jun 6, 2016 |
| Suse | — | Upgrade libspice-server1Upgrade libspice-server-devel | Jun 13, 2016 | Jun 9, 2016 |
| Ubuntu | — | Upgrade libspice-server1 | Jun 21, 2016 | Jun 9, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub