Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-10893

Опубликовано: 11 сент. 2018
Источник: debian

Описание

Multiple integer overflow and buffer overflow issues were discovered in spice-client's handling of LZ compressed frames. A malicious server could cause the client to crash or, potentially, execute arbitrary code.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
spice-gtkfixed0.37-1package
spice-gtkno-dsabusterpackage
spice-gtkno-dsastretchpackage
spice-gtkno-dsajessiepackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=1598234

  • Ongoing patch review: https://lists.freedesktop.org/archives/spice-devel/2018-July/044489.html

  • https://gitlab.freedesktop.org/spice/spice-common/-/commit/3050b4e1f6f39c1a9f8a286791d06705fce1ecb7

  • https://gitlab.freedesktop.org/spice/spice-common/-/commit/5173ff871a7df11e230124b4d1724653ebaa7134

Связанные уязвимости

CVSS3: 7.6
ubuntu
больше 7 лет назад

Multiple integer overflow and buffer overflow issues were discovered in spice-client's handling of LZ compressed frames. A malicious server could cause the client to crash or, potentially, execute arbitrary code.

CVSS3: 7.6
redhat
больше 7 лет назад

Multiple integer overflow and buffer overflow issues were discovered in spice-client's handling of LZ compressed frames. A malicious server could cause the client to crash or, potentially, execute arbitrary code.

CVSS3: 7.6
nvd
больше 7 лет назад

Multiple integer overflow and buffer overflow issues were discovered in spice-client's handling of LZ compressed frames. A malicious server could cause the client to crash or, potentially, execute arbitrary code.

CVSS3: 8.8
github
больше 3 лет назад

Multiple integer overflow and buffer overflow issues were discovered in spice-client's handling of LZ compressed frames. A malicious server could cause the client to crash or, potentially, execute arbitrary code.

oracle-oval
почти 6 лет назад

ELSA-2020-0471: spice-gtk security update (MODERATE)