cbcvebase.
CVE-2015-3247
published 2015-09-08

CVE-2015-3247: Race condition in the worker_update_monitors_config function in SPICE 0.12.4 allows a remote authenticated guest user to cause a denial of service (heap-based…

medium6.9CVSS 3.1
AVLACMAuNCCICAC
Race condition in the worker_update_monitors_config function in SPICE 0.12.4 allows a remote authenticated guest user to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) or possibly execute arbitrary code on the host via unspecified vectors.

Affected

16 ranges
VendorProductVersion rangeFixed in
debianspice< spice 0.12.5-1.2 (bookworm)spice 0.12.5-1.2 (bookworm)
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux_desktop
redhatenterprise_linux_desktop
redhatenterprise_linux_hpc_node
redhatenterprise_linux_hpc_node
redhatenterprise_linux_server
redhatenterprise_linux_server
redhatenterprise_linux_workstation
redhatenterprise_linux_workstation
spice_projectspice
spice_projectspice>= 0 < 0.12.5-1.20.12.5-1.2
spice_projectspice>= 0 < 0.12.5-1.20.12.5-1.2
spice_projectspice>= 0 < 0.12.5-1.20.12.5-1.2
spice_projectspice>= 0 < 0.12.5-1.20.12.5-1.2

CVSS provenance

nvd6.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv6.9MEDIUM