A flaw was found in the way spice-client processed certain messages sent from the server. An attacker, having control of malicious spice-server, could use this flaw to crash the client or execute arbitrary code with permissions of the user running the client. spice-gtk versions through 0.34 are believed to be vulnerable.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade spice-gtk | Jul 30, 2024 | Mar 14, 2018 |
| Gentoo Linux | — | Upgrade net-misc/spice-gtk. | Nov 27, 2018 | Mar 14, 2018 |
| Huawei Euleros 2_0_sp1 | — | Upgrade spice-gtk3Upgrade spice-glib | May 29, 2018 | Mar 14, 2018 |
| Huawei Euleros 2_0_sp2 | — | Upgrade spice-gtk3Upgrade spice-glib | May 29, 2018 | Mar 14, 2018 |
| Huawei Euleros 2_0_sp3 | — | Upgrade spice-gtk3Upgrade spice-glib | Jan 20, 2021 | Mar 14, 2018 |
| Huawei Euleros 2_0_sp5 | — | Upgrade spice-glibUpgrade spice-gtk3 | Feb 3, 2021 | Mar 14, 2018 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Mar 14, 2018 |
| Suse | — | Upgrade libspice-client-glib-helperUpgrade libspice-controller0Upgrade typelib-1_0-spiceclientgtk-3_0Upgrade typelib-1_0-spiceclientglib-2_0Upgrade libspice-client-glib-2_0-8Upgrade libspice-client-gtk-3_0-5Upgrade spice-gtk-devel | Apr 6, 2018 | Mar 14, 2018 |
| Ubuntu | — | Upgrade libspice-server1Upgrade libspice-protocol-dev | Jun 1, 2018 | Mar 14, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub