Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-12194

Опубликовано: 14 мар. 2018
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

A flaw was found in the way spice-client processed certain messages sent from the server. An attacker, having control of malicious spice-server, could use this flaw to crash the client or execute arbitrary code with permissions of the user running the client. spice-gtk versions through 0.34 are believed to be vulnerable.

A flaw was found in the way spice-client processed certain messages sent from the server. An attacker, having control of malicious spice-server, could use this flaw to crash the client or execute arbitrary code with permissions of the user running the client.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6spice-gtkWill not fix
Red Hat Enterprise Linux 7spice-gtkWill not fix
Red Hat Enterprise Linux 8spice-gtkNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-121
https://bugzilla.redhat.com/show_bug.cgi?id=1501200spice-gtk: Integer overflows causing buffer overflows in spice-client

EPSS

Процентиль: 81%
0.01485
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 8 лет назад

A flaw was found in the way spice-client processed certain messages sent from the server. An attacker, having control of malicious spice-server, could use this flaw to crash the client or execute arbitrary code with permissions of the user running the client. spice-gtk versions through 0.34 are believed to be vulnerable.

CVSS3: 9.8
nvd
почти 8 лет назад

A flaw was found in the way spice-client processed certain messages sent from the server. An attacker, having control of malicious spice-server, could use this flaw to crash the client or execute arbitrary code with permissions of the user running the client. spice-gtk versions through 0.34 are believed to be vulnerable.

CVSS3: 9.8
debian
почти 8 лет назад

A flaw was found in the way spice-client processed certain messages se ...

suse-cvrf
почти 8 лет назад

Security update for spice-gtk

suse-cvrf
почти 8 лет назад

Security update for spice-gtk

EPSS

Процентиль: 81%
0.01485
Низкий

5.5 Medium

CVSS3