CVE Database
/

CVE-2018-10873

Back to search

CVE-2018-10873

Published: Aug 17, 2018

Modified: Aug 5, 2024

PUBLISHED

CVSS v3.0

8.3

HIGH

Description

A vulnerability was discovered in SPICE before version 0.14.1 where the generated code used for demarshalling messages lacked sufficient bounds checks. A malicious client or server, after authentication, could send specially crafted messages to its peer which would result in a crash or, potentially, other impacts.

VendorProductVersions

[UNKNOWN]

spice:

affected
0.14.1

Weaknesses (CWE)

CVSS v3.0 Details

CVSS v3.0 Vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H

Attack Vector

Network

Attack Complexity

Low

Privileges Required

Low

User Interaction

None

Scope

Unchanged

Confidentiality

High

Integrity

Low

Availability

High

References

DSA-4319
vendor-advisory
x_refsource_DEBIAN
USN-3751-1
vendor-advisory
x_refsource_UBUNTU
RHSA-2018:2732
vendor-advisory
x_refsource_REDHAT
RHSA-2018:2731
vendor-advisory
x_refsource_REDHAT
RHSA-2018:3470
vendor-advisory
x_refsource_REDHAT
105152
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now