ZeroHour

CVE-2019-3813

CVSS 3.1
7.5 high
EPSS
1%p67
Published
()
Modified
Description

Spice, versions 0.5.2 through 0.14.1, are vulnerable to an out-of-bounds read due to an off-by-one error in memslot_get_virt. This may lead to a denial of service, or, in the worst case, code-execution by unauthenticated attackers.

Vendors
spice projectredhatdebiancanonical
Products
spice, enterprise linux desktop, enterprise linux server, enterprise linux server aus, enterprise linux server eus, enterprise linux server tus, enterprise linux workstation, debian linux, ubuntu linux
Weakness
CWE-193
Vector
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.