Описание
A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An authenticated attacker could send crafted messages to the SPICE server causing a heap overflow leading to a crash or possible code execution.
A vulnerability was discovered in SPICE in the server's protocol handling. An authenticated attacker could send crafted messages to the SPICE server causing a heap overflow leading to a crash or possible code execution.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Virtualization 4 | distribution | Affected | ||
| Red Hat Enterprise Linux 6 | spice-server | Fixed | RHSA-2017:0253 | 06.02.2017 |
| Red Hat Enterprise Linux 7 | spice | Fixed | RHSA-2017:0254 | 06.02.2017 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | imgbased | Fixed | RHSA-2017:0549 | 16.03.2017 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | redhat-release-virtualization-host | Fixed | RHSA-2017:0549 | 16.03.2017 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | redhat-virtualization-host | Fixed | RHSA-2017:0549 | 16.03.2017 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | rhevm-appliance | Fixed | RHSA-2017:0552 | 16.03.2017 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
6 Medium
CVSS2
Связанные уязвимости
A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An authenticated attacker could send crafted messages to the SPICE server causing a heap overflow leading to a crash or possible code execution.
A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An authenticated attacker could send crafted messages to the SPICE server causing a heap overflow leading to a crash or possible code execution.
A vulnerability was discovered in SPICE before 0.13.90 in the server's ...
A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An authenticated attacker could send crafted messages to the SPICE server causing a heap overflow leading to a crash or possible code execution.
EPSS
7.5 High
CVSS3
6 Medium
CVSS2