Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-10893

Опубликовано: 25 июн. 2018
Источник: redhat
CVSS3: 7.6
EPSS Низкий

Описание

Multiple integer overflow and buffer overflow issues were discovered in spice-client's handling of LZ compressed frames. A malicious server could cause the client to crash or, potentially, execute arbitrary code.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6spice-clientWill not fix
Red Hat Enterprise Linux 8spice-gtkNot affected
Red Hat Enterprise Linux 6spice-gtkFixedRHSA-2020:047111.02.2020
Red Hat Enterprise Linux 7libgovirtFixedRHSA-2019:222906.08.2019
Red Hat Enterprise Linux 7spice-gtkFixedRHSA-2019:222906.08.2019
Red Hat Enterprise Linux 7spice-vdagentFixedRHSA-2019:222906.08.2019
Red Hat Enterprise Linux 7virt-viewerFixedRHSA-2019:222906.08.2019

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-122
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=1598234spice-client: Insufficient encoding checks for LZ can cause different integer/buffer overflows

EPSS

Процентиль: 57%
0.00348
Низкий

7.6 High

CVSS3

Связанные уязвимости

CVSS3: 7.6
ubuntu
больше 7 лет назад

Multiple integer overflow and buffer overflow issues were discovered in spice-client's handling of LZ compressed frames. A malicious server could cause the client to crash or, potentially, execute arbitrary code.

CVSS3: 7.6
nvd
больше 7 лет назад

Multiple integer overflow and buffer overflow issues were discovered in spice-client's handling of LZ compressed frames. A malicious server could cause the client to crash or, potentially, execute arbitrary code.

CVSS3: 7.6
debian
больше 7 лет назад

Multiple integer overflow and buffer overflow issues were discovered i ...

CVSS3: 8.8
github
больше 3 лет назад

Multiple integer overflow and buffer overflow issues were discovered in spice-client's handling of LZ compressed frames. A malicious server could cause the client to crash or, potentially, execute arbitrary code.

oracle-oval
почти 6 лет назад

ELSA-2020-0471: spice-gtk security update (MODERATE)

EPSS

Процентиль: 57%
0.00348
Низкий

7.6 High

CVSS3