A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An authenticated attacker could send crafted messages to the SPICE server causing a heap overflow leading to a crash or possible code execution.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-spice | Aug 22, 2024 | Jul 27, 2018 | |
| Centos_linux | — | centos-upgrade-spice-debuginfocentos-upgrade-spice-servercentos-upgrade-spice-server-debuginfocentos-upgrade-spice-server-devel | Feb 7, 2017 | Feb 6, 2017 |
| Debian | debian-upgrade-spice | Feb 18, 2017 | Feb 6, 2017 | |
| Huawei Euleros 2_0_sp2 | huawei-euleros-2_0_sp2-upgrade-spice-server | Aug 28, 2019 | Jul 27, 2018 | |
| Oracle_linux | — | oracle-linux-upgrade-spice-serveroracle-linux-upgrade-spice-server-devel | Feb 6, 2017 | Feb 6, 2017 |
| Redhat_linux | — | redhat-upgrade-spice-debuginforedhat-upgrade-spice-serverredhat-upgrade-spice-server-debuginforedhat-upgrade-spice-server-devel | Feb 6, 2017 | Feb 6, 2017 |
| Suse | — | suse-upgrade-libspice-server-develsuse-upgrade-libspice-server1 | Feb 7, 2017 | Feb 6, 2017 |
| Ubuntu | ubuntu-upgrade-libspice-server1 | Feb 21, 2017 | Feb 6, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub