CVE-2010-2792

CWE-362Race Condition5 documents5 sources
Severity
3.3LOW
EPSS
0.0%
top 85.01%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 30
Latest updateMay 17

Description

Race condition in the SPICE (aka spice-xpi) plug-in 2.2 for Firefox allows local users to obtain sensitive information, and conduct man-in-the-middle attacks, by providing a UNIX socket for communication between this plug-in and the client (aka qspice-client) in qspice 0.3.0, and then accessing this socket.

CVSS vector

AV:L/AC:M/C:P/I:P/A:NExploitability: 3.4 | Impact: 4.9

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-jj4v-3jp4-pvcr: Race condition in the SPICE (aka spice-xpi) plug-in 22022-05-17
CVEList
CVE-2010-2792: Race condition in the SPICE (aka spice-xpi) plug-in 22010-08-30

📋Vendor Advisories

1
Red Hat
spice-xpi/qspice-client unix socket race2010-08-25

💬Community

1
Bugzilla
CVE-2010-2792 spice-xpi/qspice-client unix socket race2010-08-02
CVE-2010-2792 (LOW CVSS 3.3) | Race condition in the SPICE (aka sp | cvebase.io