CVE-2010-0430
published 2013-12-27CVE-2010-0430: libspice, as used in QEMU-KVM in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H or rhev-hypervisor) before 5.5-2.2 and possibly other products…
PriorityP430high7.4CVSS 2.0
AVAACMAuSCCICAC
EPSS
0.49%
38.5th percentile
libspice, as used in QEMU-KVM in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H or rhev-hypervisor) before 5.5-2.2 and possibly other products, allows guest OS users to read from or write to arbitrary QEMU memory by modifying the address that is used by Cairo for memory mappings.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | spice | — | — |
| redhat | enterprise_virtualization_hypervisor | <= 5.4-2.1 | — |
CVSS provenance
nvdv2.07.4HIGHAV:A/AC:M/Au:S/C:C/I:C/A:C
vendor_debian7.4LOW
vendor_redhat7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
libspice: Insufficient guest provided memory mappings boundaries validations
vendor_redhat·2010-03-30·CVSS 7.4
CVE-2010-0430 [HIGH] libspice: Insufficient guest provided memory mappings boundaries validations
libspice: Insufficient guest provided memory mappings boundaries validations
libspice, as used in QEMU-KVM in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H or rhev-hypervisor) before 5.5-2.2 and possibly other products, allows guest OS users to read from or write to arbitrary QEMU memory by modifying the address that is used by Cairo for memory mappings.
Statement: The CVE-2010-0430 issue was fixed in the kvm packages for Red Hat Enterprise Linux 5 via RHSA-2010:0271, and fixed in the rhev-hypervisor package via RHSA-2010:0476. This CVE was not disclosed at the time the errata were released; therefore, it was not mentioned in them.
Debian
CVE-2010-0430: spice - libspice, as used in QEMU-KVM in Red Hat Enterprise Virtualization Hypervisor (a...
vendor_debian·2010·CVSS 7.4
CVE-2010-0430 [HIGH] CVE-2010-0430: spice - libspice, as used in QEMU-KVM in Red Hat Enterprise Virtualization Hypervisor (a...
libspice, as used in QEMU-KVM in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H or rhev-hypervisor) before 5.5-2.2 and possibly other products, allows guest OS users to read from or write to arbitrary QEMU memory by modifying the address that is used by Cairo for memory mappings.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-5g9q-h772-m2pq: libspice, as used in QEMU-KVM in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H or rhev-hypervisor) before 5
ghsa_unreviewed·2022-05-02
CVE-2010-0430 [HIGH] CWE-119 GHSA-5g9q-h772-m2pq: libspice, as used in QEMU-KVM in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H or rhev-hypervisor) before 5
libspice, as used in QEMU-KVM in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H or rhev-hypervisor) before 5.5-2.2 and possibly other products, allows guest OS users to read from or write to arbitrary QEMU memory by modifying the address that is used by Cairo for memory mappings.
No detection rules found.
2013-12-27
Published