Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-12194

Опубликовано: 14 мар. 2018
Источник: debian
EPSS Низкий

Описание

A flaw was found in the way spice-client processed certain messages sent from the server. An attacker, having control of malicious spice-server, could use this flaw to crash the client or execute arbitrary code with permissions of the user running the client. spice-gtk versions through 0.34 are believed to be vulnerable.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
spice-gtkfixed0.35-1package
spice-gtkno-dsastretchpackage
spice-gtkno-dsajessiepackage
spice-gtknot-affectedwheezypackage

Примечания

  • Proposed patches in: https://bugzilla.redhat.com/show_bug.cgi?id=1240165

  • Although not present in the binary packages the (de)marshal.py are used to

  • generate repsecitve code which should be in libspice-common-client.

EPSS

Процентиль: 81%
0.01485
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 8 лет назад

A flaw was found in the way spice-client processed certain messages sent from the server. An attacker, having control of malicious spice-server, could use this flaw to crash the client or execute arbitrary code with permissions of the user running the client. spice-gtk versions through 0.34 are believed to be vulnerable.

CVSS3: 5.5
redhat
почти 8 лет назад

A flaw was found in the way spice-client processed certain messages sent from the server. An attacker, having control of malicious spice-server, could use this flaw to crash the client or execute arbitrary code with permissions of the user running the client. spice-gtk versions through 0.34 are believed to be vulnerable.

CVSS3: 9.8
nvd
почти 8 лет назад

A flaw was found in the way spice-client processed certain messages sent from the server. An attacker, having control of malicious spice-server, could use this flaw to crash the client or execute arbitrary code with permissions of the user running the client. spice-gtk versions through 0.34 are believed to be vulnerable.

suse-cvrf
почти 8 лет назад

Security update for spice-gtk

suse-cvrf
почти 8 лет назад

Security update for spice-gtk

EPSS

Процентиль: 81%
0.01485
Низкий