Severity
5.0MEDIUM
EPSS
1.5%
top 18.81%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 2
Latest updateMay 14

Description

Stack-based buffer overflow in the reds_handle_ticket function in server/reds.c in SPICE 0.12.0 allows remote attackers to cause a denial of service (crash) via a long password in a SPICE ticket.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

Debianspice< 0.12.4-0nocelt2+3

Also affects: Enterprise Linux 5, 6.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-wr45-fcg3-r672: Stack-based buffer overflow in the reds_handle_ticket function in server/reds2022-05-14
OSV
CVE-2013-4282: Stack-based buffer overflow in the reds_handle_ticket function in server/reds2013-11-02
CVEList
CVE-2013-4282: Stack-based buffer overflow in the reds_handle_ticket function in server/reds2013-11-02

📋Vendor Advisories

3
Ubuntu
SPICE vulnerability2013-11-12
Red Hat
spice: stack buffer overflow in reds_handle_ticket() function2013-10-29
Debian
CVE-2013-4282: spice - Stack-based buffer overflow in the reds_handle_ticket function in server/reds.c ...2013

💬Community

1
Bugzilla
CVE-2013-4282 spice: stack buffer overflow in reds_handle_ticket() function2013-08-23