CVE-2016-9578
published 2018-07-27CVE-2016-9578: A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An attacker able to connect to the SPICE server could send crafted…
PriorityP339high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
2.49%
82.9th percentile
A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An attacker able to connect to the SPICE server could send crafted messages which would cause the process to crash.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | spice | < spice 0.12.8-2.1 (bookworm) | spice 0.12.8-2.1 (bookworm) |
| red_hat | spice | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
| spice_project | spice | < 0.13.90 | 0.13.90 |
| spice_project | spice | >= 0 < 0.12.8-2.1 | 0.12.8-2.1 |
| spice_project | spice | >= 0 < 0.12.8-2.1 | 0.12.8-2.1 |
| spice_project | spice | >= 0 < 0.12.8-2.1 | 0.12.8-2.1 |
| spice_project | spice | >= 0 < 0.12.8-2.1 | 0.12.8-2.1 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Spice vulnerabilities
vendor_ubuntu·2017-02-20
CVE-2016-9577 Spice vulnerabilities
Title: Spice vulnerabilities
Summary: Spice could be made to crash or run programs if it received specially
crafted network traffic.
Frediano Ziglio discovered that Spice incorrectly handled certain client
messages. A remote attacker could use this issue to cause Spice to crash,
resulting in a denial of service, or possibly execute arbitrary code.
Instructions: After a standard system update you need to restart qemu guests to make
all the necessary changes.
Red Hat
spice: Remote DoS via crafted message
vendor_redhat·2017-02-06·CVSS 7.5
CVE-2016-9578 [HIGH] CWE-1286 spice: Remote DoS via crafted message
spice: Remote DoS via crafted message
A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An attacker able to connect to the SPICE server could send crafted messages which would cause the process to crash.
A vulnerability was discovered in SPICE in the server's protocol handling. An attacker able to connect to the SPICE server could send crafted messages which would cause the process to crash.
Package: distribution (Red Hat Virtualization 4) - Affected
Debian
CVE-2016-9578: spice - A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol ...
vendor_debian·2016·CVSS 7.5
CVE-2016-9578 [HIGH] CVE-2016-9578: spice - A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol ...
A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An attacker able to connect to the SPICE server could send crafted messages which would cause the process to crash.
Scope: local
bookworm: resolved (fixed in 0.12.8-2.1)
bullseye: resolved (fixed in 0.12.8-2.1)
forky: resolved (fixed in 0.12.8-2.1)
sid: resolved (fixed in 0.12.8-2.1)
trixie: resolved (fixed in 0.12.8-2.1)
GHSA
GHSA-9m3r-8p8r-j38x: A vulnerability was discovered in SPICE before 0
ghsa_unreviewed·2022-05-13
CVE-2016-9578 [HIGH] CWE-20 GHSA-9m3r-8p8r-j38x: A vulnerability was discovered in SPICE before 0
A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An attacker able to connect to the SPICE server could send crafted messages which would cause the process to crash.
OSV
CVE-2016-9578: A vulnerability was discovered in SPICE before 0
osv·2018-07-27·CVSS 7.5
CVE-2016-9578 [HIGH] CVE-2016-9578: A vulnerability was discovered in SPICE before 0
A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An attacker able to connect to the SPICE server could send crafted messages which would cause the process to crash.
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2017-0253.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0549.htmlhttp://www.securityfocus.com/bid/96118https://access.redhat.com/errata/RHSA-2017:0254https://access.redhat.com/errata/RHSA-2017:0552https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-9578https://www.debian.org/security/2017/dsa-3790http://rhn.redhat.com/errata/RHSA-2017-0253.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0549.htmlhttp://www.securityfocus.com/bid/96118https://access.redhat.com/errata/RHSA-2017:0254https://access.redhat.com/errata/RHSA-2017:0552https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-9578https://www.debian.org/security/2017/dsa-3790
2018-07-27
Published