ZeroHour

CVE-2018-10873

CVSS 3.0
8.8 high
EPSS
4%p90
Published
()
Modified
Description

A vulnerability was discovered in SPICE before version 0.14.1 where the generated code used for demarshalling messages lacked sufficient bounds checks. A malicious client or server, after authentication, could send specially crafted messages to its peer which would result in a crash or, potentially, other impacts.

Vendors
spice projectdebiancanonicalredhat
Products
spice, debian linux, ubuntu linux, virtualization, virtualization host, enterprise linux desktop, enterprise linux server, enterprise linux server aus, enterprise linux server eus, enterprise linux server tus, enterprise linux workstation
Weakness
CWE-119, CWE-20
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.