Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-7506

Опубликовано: 11 июл. 2017
Источник: redhat
CVSS3: 9.1

Описание

spice versions though 0.13 are vulnerable to out-of-bounds memory access when processing specially crafted messages from authenticated attacker to the spice server resulting into crash and/or server memory leak.

A vulnerability was discovered in spice server's protocol handling. An authenticated attacker could send specially crafted messages to the spice server, causing out-of-bounds memory accesses, leading to parts of server memory being leaked or a crash.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7rhev-hypervisorAffected
Red Hat Virtualization 4distributionAffected
Red Hat Enterprise Linux 6spice-serverFixedRHSA-2018:352207.11.2018
Red Hat Enterprise Linux 7spiceFixedRHSA-2017:247115.08.2017
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7imgbasedFixedRHBA-2017:252922.08.2017
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7ovirt-node-ngFixedRHBA-2017:252922.08.2017
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7redhat-release-virtualization-hostFixedRHBA-2017:252922.08.2017
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7redhat-virtualization-hostFixedRHBA-2017:252922.08.2017

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-681->CWE-119
https://bugzilla.redhat.com/show_bug.cgi?id=1452606spice: Possible buffer overflow via invalid monitor configurations

9.1 Critical

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 8 лет назад

spice versions though 0.13 are vulnerable to out-of-bounds memory access when processing specially crafted messages from authenticated attacker to the spice server resulting into crash and/or server memory leak.

CVSS3: 8.8
nvd
больше 8 лет назад

spice versions though 0.13 are vulnerable to out-of-bounds memory access when processing specially crafted messages from authenticated attacker to the spice server resulting into crash and/or server memory leak.

CVSS3: 8.8
debian
больше 8 лет назад

spice versions though 0.13 are vulnerable to out-of-bounds memory acce ...

suse-cvrf
около 8 лет назад

Security update for spice

suse-cvrf
больше 8 лет назад

Security update for spice

9.1 Critical

CVSS3