Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2019-3813

Опубликовано: 04 фев. 2019
Источник: ubuntu
Приоритет: high
CVSS2: 5.4
CVSS3: 7.5

Описание

Spice, versions 0.5.2 through 0.14.1, are vulnerable to an out-of-bounds read due to an off-by-one error in memslot_get_virt. This may lead to a denial of service, or, in the worst case, code-execution by unauthenticated attackers.

РелизСтатусПримечание
bionic

released

0.14.0-1ubuntu2.4
cosmic

released

0.14.0-1ubuntu4.2
devel

released

0.14.0-1ubuntu5
esm-infra-legacy/trusty

released

0.12.4-0nocelt2ubuntu1.8
esm-infra/bionic

released

0.14.0-1ubuntu2.4
esm-infra/xenial

released

0.12.6-4ubuntu0.4
precise/esm

DNE

trusty

released

0.12.4-0nocelt2ubuntu1.8
trusty/esm

released

0.12.4-0nocelt2ubuntu1.8
upstream

pending

0.14.2

Показывать по

РелизСтатусПримечание
bionic

not-affected

code not present
cosmic

not-affected

code not present
devel

not-affected

code not present
esm-apps/bionic

not-affected

code not present
esm-apps/xenial

not-affected

code not present
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was not-affected [code not present]]
precise/esm

DNE

trusty

not-affected

code not present
trusty/esm

DNE

trusty was not-affected [code not present]
upstream

not-affected

code not present

Показывать по

РелизСтатусПримечание
bionic

not-affected

code not present
cosmic

not-affected

code not present
devel

not-affected

code not present
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was not-affected [code not present]]
esm-infra/bionic

not-affected

code not present
esm-infra/xenial

not-affected

code not present
precise/esm

DNE

trusty

not-affected

code not present
trusty/esm

DNE

trusty was not-affected [code not present]
upstream

not-affected

code not present

Показывать по

5.4 Medium

CVSS2

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 8
redhat
почти 7 лет назад

Spice, versions 0.5.2 through 0.14.1, are vulnerable to an out-of-bounds read due to an off-by-one error in memslot_get_virt. This may lead to a denial of service, or, in the worst case, code-execution by unauthenticated attackers.

CVSS3: 7.5
nvd
почти 7 лет назад

Spice, versions 0.5.2 through 0.14.1, are vulnerable to an out-of-bounds read due to an off-by-one error in memslot_get_virt. This may lead to a denial of service, or, in the worst case, code-execution by unauthenticated attackers.

CVSS3: 7.5
debian
почти 7 лет назад

Spice, versions 0.5.2 through 0.14.1, are vulnerable to an out-of-boun ...

suse-cvrf
почти 7 лет назад

Security update for spice

suse-cvrf
больше 6 лет назад

Security update for spice

5.4 Medium

CVSS2

7.5 High

CVSS3