PT-2011-1116 · Red Hat · Spice-Xpi+1

Petr Matousek

·

Publicado

2011-04-07

·

Atualizado

2024-03-12

·

CVE-2011-1179

CVSS v2.0

5.1

Média

VetorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions spice-xpi versions 2.2 through 2.4
Description The issue affects the confidentiality, integrity, and availability of protected information. It can be exploited remotely, potentially leading to a denial of service (crash) and possibly the execution of arbitrary code. The exploitation is related to vectors involving plugin/nsScriptablePeer.cpp and plugin/plugin.cpp, which trigger multiple uses of an uninitialized pointer.
Recommendations For versions 2.2 through 2.4, consider disabling the spice-xpi plugin as a temporary workaround until a patch is available. Restrict access to the plugin to minimize the risk of exploitation. Avoid using the affected plugin in sensitive operations until the issue is resolved.

Exploit

Correção

DoS

Buffer Overflow

Link Following

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-06538
BDU:2015-06539
CVE-2011-1179
RHSA-2011:0426
RHSA-2011:0427
RHSA-2011_0426
RHSA-2011_0427
ROSA-SA-2024-2371

Produtos afetados

Red Hat
Spice-Xpi