Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2017-12194

Опубликовано: 14 мар. 2018
Источник: ubuntu
Приоритет: medium
CVSS2: 10
CVSS3: 9.8

Описание

A flaw was found in the way spice-client processed certain messages sent from the server. An attacker, having control of malicious spice-server, could use this flaw to crash the client or execute arbitrary code with permissions of the user running the client. spice-gtk versions through 0.34 are believed to be vulnerable.

РелизСтатусПримечание
artful

released

0.12.8-2.2ubuntu0.1
bionic

released

0.14.0-1ubuntu2.1
cosmic

released

0.14.0-1ubuntu3
devel

released

0.14.0-1ubuntu3
disco

released

0.14.0-1ubuntu3
eoan

released

0.14.0-1ubuntu3
esm-infra-legacy/trusty

released

0.12.4-0nocelt2ubuntu1.6
esm-infra/bionic

released

0.14.0-1ubuntu2.1
esm-infra/focal

released

0.14.0-1ubuntu3
esm-infra/xenial

not-affected

Показывать по

РелизСтатусПримечание
artful

ignored

end of life
bionic

ignored

end of standard support, was needed
cosmic

not-affected

0.35-2
devel

not-affected

0.35-2
disco

not-affected

0.35-2
eoan

not-affected

0.35-2
esm-apps/bionic

needed

esm-apps/focal

not-affected

0.35-2
esm-apps/jammy

not-affected

0.35-2
esm-apps/noble

not-affected

0.35-2

Показывать по

РелизСтатусПримечание
artful

not-affected

bionic

not-affected

cosmic

not-affected

devel

not-affected

disco

not-affected

eoan

not-affected

esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was not-affected]
esm-infra/bionic

not-affected

esm-infra/focal

not-affected

esm-infra/xenial

released

0.12.10-1ubuntu0.1

Показывать по

10 Critical

CVSS2

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 5.5
redhat
почти 8 лет назад

A flaw was found in the way spice-client processed certain messages sent from the server. An attacker, having control of malicious spice-server, could use this flaw to crash the client or execute arbitrary code with permissions of the user running the client. spice-gtk versions through 0.34 are believed to be vulnerable.

CVSS3: 9.8
nvd
почти 8 лет назад

A flaw was found in the way spice-client processed certain messages sent from the server. An attacker, having control of malicious spice-server, could use this flaw to crash the client or execute arbitrary code with permissions of the user running the client. spice-gtk versions through 0.34 are believed to be vulnerable.

CVSS3: 9.8
debian
почти 8 лет назад

A flaw was found in the way spice-client processed certain messages se ...

suse-cvrf
почти 8 лет назад

Security update for spice-gtk

suse-cvrf
почти 8 лет назад

Security update for spice-gtk

10 Critical

CVSS2

9.8 Critical

CVSS3

Уязвимость CVE-2017-12194