PT-2017-10209 · Red Hat+4 · Spice+5

Frediano Ziglio

·

Publicado

2017-02-06

·

Atualizado

2024-06-15

·

CVE-2016-9578

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions SPICE versions prior to 0.13.90
Description A vulnerability was discovered in the server's protocol handling, allowing an attacker who can connect to the SPICE server to send crafted messages, causing the process to crash.
Recommendations For versions prior to 0.13.90, update to version 0.13.90 or later to resolve the issue.

Correção

RCE

Allocation of Resources Without Limits

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2017-2174
CESA-2017_0253
CESA-2017_0254
CVE-2016-9578
DLA-825-1
DSA-3790-1
MGASA-2017-0062
OPENSUSE-SU-2017_0419-1
OPENSUSE-SU-2017_0421-1
OPENSUSE-SU-2024:11397-1
RHSA-2017:0253
RHSA-2017:0254
RHSA-2017:0549
RHSA-2017:0552
RHSA-2017_0253
RHSA-2017_0254
SUSE-SU-2017:0392-1
SUSE-SU-2017:0393-1
SUSE-SU-2017:0396-1
SUSE-SU-2017:0400-1
USN-3202-1

Produtos afetados

Alt Linux
Centos
Red Hat
Spice
Suse
Ubuntu