Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-3813

Опубликовано: 04 фев. 2019
Источник: debian
EPSS Низкий

Описание

Spice, versions 0.5.2 through 0.14.1, are vulnerable to an out-of-bounds read due to an off-by-one error in memslot_get_virt. This may lead to a denial of service, or, in the worst case, code-execution by unauthenticated attackers.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
spicefixed0.14.0-1.3package

Примечания

  • https://www.openwall.com/lists/oss-security/2019/01/28/2

  • https://bugzilla.redhat.com/show_bug.cgi?id=1665371

EPSS

Процентиль: 49%
0.00256
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 7 лет назад

Spice, versions 0.5.2 through 0.14.1, are vulnerable to an out-of-bounds read due to an off-by-one error in memslot_get_virt. This may lead to a denial of service, or, in the worst case, code-execution by unauthenticated attackers.

CVSS3: 8
redhat
почти 7 лет назад

Spice, versions 0.5.2 through 0.14.1, are vulnerable to an out-of-bounds read due to an off-by-one error in memslot_get_virt. This may lead to a denial of service, or, in the worst case, code-execution by unauthenticated attackers.

CVSS3: 7.5
nvd
почти 7 лет назад

Spice, versions 0.5.2 through 0.14.1, are vulnerable to an out-of-bounds read due to an off-by-one error in memslot_get_virt. This may lead to a denial of service, or, in the worst case, code-execution by unauthenticated attackers.

suse-cvrf
почти 7 лет назад

Security update for spice

suse-cvrf
больше 6 лет назад

Security update for spice

EPSS

Процентиль: 49%
0.00256
Низкий