Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-3813

Опубликовано: 28 янв. 2019
Источник: redhat
CVSS3: 8
EPSS Низкий

Описание

Spice, versions 0.5.2 through 0.14.1, are vulnerable to an out-of-bounds read due to an off-by-one error in memslot_get_virt. This may lead to a denial of service, or, in the worst case, code-execution by unauthenticated attackers.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8spiceNot affected
Red Hat Enterprise Linux 6spice-serverFixedRHSA-2019:023231.01.2019
Red Hat Enterprise Linux 7spiceFixedRHSA-2019:023131.01.2019
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7redhat-release-virtualization-hostFixedRHSA-2019:045705.03.2019
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7redhat-virtualization-hostFixedRHSA-2019:045705.03.2019

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-193
https://bugzilla.redhat.com/show_bug.cgi?id=1665371spice: Off-by-one error in array access in spice/server/memslot.c

EPSS

Процентиль: 49%
0.00256
Низкий

8 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 7 лет назад

Spice, versions 0.5.2 through 0.14.1, are vulnerable to an out-of-bounds read due to an off-by-one error in memslot_get_virt. This may lead to a denial of service, or, in the worst case, code-execution by unauthenticated attackers.

CVSS3: 7.5
nvd
почти 7 лет назад

Spice, versions 0.5.2 through 0.14.1, are vulnerable to an out-of-bounds read due to an off-by-one error in memslot_get_virt. This may lead to a denial of service, or, in the worst case, code-execution by unauthenticated attackers.

CVSS3: 7.5
debian
почти 7 лет назад

Spice, versions 0.5.2 through 0.14.1, are vulnerable to an out-of-boun ...

suse-cvrf
почти 7 лет назад

Security update for spice

suse-cvrf
больше 6 лет назад

Security update for spice

EPSS

Процентиль: 49%
0.00256
Низкий

8 High

CVSS3