PT-2018-1152 · Red Hat+3 · Spice-Gtk+3

Frediano Ziglio

·

Published

2018-03-14

·

Updated

2019-06-17

·

CVE-2017-12194

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions spice-gtk versions through 0.34
Description A flaw in the spice-client's message processing from the server allows an attacker with control of a malicious spice-server to potentially crash the client or execute arbitrary code with the permissions of the user running the client. The issue is related to insufficient input validation, which can be exploited by a remote attacker using specially crafted server messages.
Recommendations For spice-gtk versions through 0.34, consider disabling the spice-client until a patch is available to prevent potential exploitation. Restrict access to the spice-server to minimize the risk of remote attackers sending malicious messages. Avoid using the spice-client with untrusted spice-servers until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Stack Overflow

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-1998
BDU:2018-00589
CVE-2017-12194
MGASA-2019-0099
SUSE-SU-2018:0877-1
SUSE-SU-2018_0877-1
USN-3659-1

Affected Products

Alt Linux
Suse
Ubuntu
Spice-Gtk