PT-2017-10209 · Red Hat+4 · Spice+5

Frediano Ziglio

·

Published

2017-02-06

·

Updated

2024-06-15

·

CVE-2016-9578

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions SPICE versions prior to 0.13.90
Description A vulnerability was discovered in the server's protocol handling, allowing an attacker who can connect to the SPICE server to send crafted messages, causing the process to crash.
Recommendations For versions prior to 0.13.90, update to version 0.13.90 or later to resolve the issue.

Fix

RCE

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-2174
CESA-2017_0253
CESA-2017_0254
CVE-2016-9578
DLA-825-1
DSA-3790-1
MGASA-2017-0062
OPENSUSE-SU-2017_0419-1
OPENSUSE-SU-2017_0421-1
OPENSUSE-SU-2024:11397-1
RHSA-2017:0253
RHSA-2017:0254
RHSA-2017:0549
RHSA-2017:0552
RHSA-2017_0253
RHSA-2017_0254
SUSE-SU-2017:0392-1
SUSE-SU-2017:0393-1
SUSE-SU-2017:0396-1
SUSE-SU-2017:0400-1
USN-3202-1

Affected Products

Alt Linux
Centos
Red Hat
Spice
Suse
Ubuntu