A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An attacker able to connect to the SPICE server could send crafted messages which would cause the process to crash.
References
Link | Resource |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-9578 | Issue Tracking Third Party Advisory |
https://www.debian.org/security/2017/dsa-3790 | Third Party Advisory |
https://access.redhat.com/errata/RHSA-2017:0552 | Third Party Advisory |
https://access.redhat.com/errata/RHSA-2017:0254 | Third Party Advisory |
http://www.securityfocus.com/bid/96118 | Third Party Advisory VDB Entry |
http://rhn.redhat.com/errata/RHSA-2017-0549.html | Third Party Advisory |
http://rhn.redhat.com/errata/RHSA-2017-0253.html | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Information
Published : 2018-07-27 14:29
Updated : 2019-10-09 16:20
NVD link : CVE-2016-9578
Mitre link : CVE-2016-9578
JSON object : View
CWE
CWE-20
Improper Input Validation
Products Affected
redhat
- enterprise_linux_desktop
- enterprise_linux_server_aus
- enterprise_linux_workstation
- enterprise_linux_server_eus
- enterprise_linux_server
debian
- debian_linux
spice_project
- spice