CVE-2013-4282
published 2013-11-02CVE-2013-4282: Stack-based buffer overflow in the reds_handle_ticket function in server/reds.c in SPICE 0.12.0 allows remote attackers to cause a denial of service (crash)…
PriorityP429medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.73%
84.4th percentile
Stack-based buffer overflow in the reds_handle_ticket function in server/reds.c in SPICE 0.12.0 allows remote attackers to cause a denial of service (crash) via a long password in a SPICE ticket.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | spice | < spice 0.12.4-0nocelt2 (bookworm) | spice 0.12.4-0nocelt2 (bookworm) |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_virtualization | — | — |
| spice_project | spice | — | — |
| spice_project | spice | >= 0 < 0.12.4-0nocelt2 | 0.12.4-0nocelt2 |
| spice_project | spice | >= 0 < 0.12.4-0nocelt2 | 0.12.4-0nocelt2 |
| spice_project | spice | >= 0 < 0.12.4-0nocelt2 | 0.12.4-0nocelt2 |
| spice_project | spice | >= 0 < 0.12.4-0nocelt2 | 0.12.4-0nocelt2 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
SPICE vulnerability
vendor_ubuntu·2013-11-12
CVE-2013-4282 SPICE vulnerability
Title: SPICE vulnerability
Summary: SPICE could be made to crash if it received specially crafted network
traffic.
Tomas Jamrisko discovered that SPICE incorrectly handled long passwords in
SPICE tickets. An attacker could use this issue to cause the SPICE server
to crash, resulting in a denial of service.
Instructions: After a standard system update you need to restart applications using the
SPICE protocol, such as QEMU, to make all the necessary changes.
Red Hat
spice: stack buffer overflow in reds_handle_ticket() function
vendor_redhat·2013-10-29·CVSS 5.0
CVE-2013-4282 [MEDIUM] CWE-121 spice: stack buffer overflow in reds_handle_ticket() function
spice: stack buffer overflow in reds_handle_ticket() function
Stack-based buffer overflow in the reds_handle_ticket function in server/reds.c in SPICE 0.12.0 allows remote attackers to cause a denial of service (crash) via a long password in a SPICE ticket.
Package: spice (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2013-4282: spice - Stack-based buffer overflow in the reds_handle_ticket function in server/reds.c ...
vendor_debian·2013·CVSS 5.0
CVE-2013-4282 [MEDIUM] CVE-2013-4282: spice - Stack-based buffer overflow in the reds_handle_ticket function in server/reds.c ...
Stack-based buffer overflow in the reds_handle_ticket function in server/reds.c in SPICE 0.12.0 allows remote attackers to cause a denial of service (crash) via a long password in a SPICE ticket.
Scope: local
bookworm: resolved (fixed in 0.12.4-0nocelt2)
bullseye: resolved (fixed in 0.12.4-0nocelt2)
forky: resolved (fixed in 0.12.4-0nocelt2)
sid: resolved (fixed in 0.12.4-0nocelt2)
trixie: resolved (fixed in 0.12.4-0nocelt2)
GHSA
GHSA-wr45-fcg3-r672: Stack-based buffer overflow in the reds_handle_ticket function in server/reds
ghsa_unreviewed·2022-05-14
CVE-2013-4282 [MEDIUM] CWE-119 GHSA-wr45-fcg3-r672: Stack-based buffer overflow in the reds_handle_ticket function in server/reds
Stack-based buffer overflow in the reds_handle_ticket function in server/reds.c in SPICE 0.12.0 allows remote attackers to cause a denial of service (crash) via a long password in a SPICE ticket.
OSV
CVE-2013-4282: Stack-based buffer overflow in the reds_handle_ticket function in server/reds
osv·2013-11-02·CVSS 5.0
CVE-2013-4282 [MEDIUM] CVE-2013-4282: Stack-based buffer overflow in the reds_handle_ticket function in server/reds
Stack-based buffer overflow in the reds_handle_ticket function in server/reds.c in SPICE 0.12.0 allows remote attackers to cause a denial of service (crash) via a long password in a SPICE ticket.
No detection rules found.
No public exploits indexed.
http://cgit.freedesktop.org/spice/spice/commit/?id=8af619009660b24e0b41ad26b30289eea288fcc2http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00008.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1460.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1473.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1474.htmlhttp://www.debian.org/security/2014/dsa-2839http://www.securityfocus.com/bid/63408http://www.ubuntu.com/usn/USN-2027-1http://cgit.freedesktop.org/spice/spice/commit/?id=8af619009660b24e0b41ad26b30289eea288fcc2http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00008.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1460.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1473.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1474.htmlhttp://www.debian.org/security/2014/dsa-2839http://www.securityfocus.com/bid/63408http://www.ubuntu.com/usn/USN-2027-1
2013-11-02
Published