ZeroHour

CVE-2016-9577

CVSS 3.0
8.8 high
EPSS
4%p89
Published
()
Modified
Description

A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An authenticated attacker could send crafted messages to the SPICE server causing a heap overflow leading to a crash or possible code execution.

Vendors
spice projectdebianredhat
Products
spice, debian linux, enterprise linux desktop, enterprise linux server, enterprise linux server aus, enterprise linux server eus, enterprise linux workstation
Weakness
CWE-20, CWE-122, CWE-119
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.