Back to search
CVE-2019-3813
Published: Feb 4, 2019
Modified: Sep 16, 2024
PUBLISHED
Description
Spice, versions 0.5.2 through 0.14.1, are vulnerable to an out-of-bounds read due to an off-by-one error in memslot_get_virt. This may lead to a denial of service, or, in the worst case, code-execution by unauthenticated attackers.
| Vendor | Product | Versions |
|---|---|---|
Red Hat, Inc. | Spice | affected versions 0.5.2 through 0.14.1 |
References
DSA-4375
vendor-advisory
x_refsource_DEBIAN
RHSA-2019:0231
vendor-advisory
x_refsource_REDHAT
106801
vdb-entry
x_refsource_BID
RHSA-2019:0457
vendor-advisory
x_refsource_REDHAT
https://bugzilla.redhat.com/show_bug.cgi?id=1665371
x_refsource_CONFIRM
USN-3870-1
vendor-advisory
x_refsource_UBUNTU
RHSA-2019:0232
vendor-advisory
x_refsource_REDHAT
[debian-lts-announce] 20190130 [SECURITY] [DLA 1649-1] spice security update
mailing-list
x_refsource_MLIST
GLSA-202007-30
vendor-advisory
x_refsource_GENTOO
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now