CVE Database
/

CVE-2019-3813

Back to search

CVE-2019-3813

Published: Feb 4, 2019

Modified: Sep 16, 2024

PUBLISHED

Description

Spice, versions 0.5.2 through 0.14.1, are vulnerable to an out-of-bounds read due to an off-by-one error in memslot_get_virt. This may lead to a denial of service, or, in the worst case, code-execution by unauthenticated attackers.

VendorProductVersions

Red Hat, Inc.

Spice

affected
versions 0.5.2 through 0.14.1

References

DSA-4375
vendor-advisory
x_refsource_DEBIAN
RHSA-2019:0231
vendor-advisory
x_refsource_REDHAT
106801
vdb-entry
x_refsource_BID
RHSA-2019:0457
vendor-advisory
x_refsource_REDHAT
USN-3870-1
vendor-advisory
x_refsource_UBUNTU
RHSA-2019:0232
vendor-advisory
x_refsource_REDHAT
GLSA-202007-30
vendor-advisory
x_refsource_GENTOO

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now