Vulnerability CVE-2016-9578


Published: 2018-07-27

Description:
A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An attacker able to connect to the SPICE server could send crafted messages which would cause the process to crash.

Type:

CWE-20

(Improper Input Validation)

CVSS2 => (AV:N/AC:L/Au:N/C:N/I:N/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5/10
2.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
None
None
Partial
Affected software
Spice project -> Spice 
Redhat -> Enterprise linux desktop 
Redhat -> Enterprise linux server 
Redhat -> Enterprise linux server aus 
Redhat -> Enterprise linux server eus 
Redhat -> Enterprise linux workstation 
Debian -> Debian linux 

 References:
http://rhn.redhat.com/errata/RHSA-2017-0253.html
http://rhn.redhat.com/errata/RHSA-2017-0549.html
http://www.securityfocus.com/bid/96118
https://access.redhat.com/errata/RHSA-2017:0254
https://access.redhat.com/errata/RHSA-2017:0552
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-9578
https://www.debian.org/security/2017/dsa-3790

Copyright 2024, cxsecurity.com

 

Back to Top