CVE-2017-7506
published 2017-07-18CVE-2017-7506: spice versions though 0.13 are vulnerable to out-of-bounds memory access when processing specially crafted messages from authenticated attacker to the spice…
PriorityP351high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
4.20%
89.8th percentile
spice versions though 0.13 are vulnerable to out-of-bounds memory access when processing specially crafted messages from authenticated attacker to the spice server resulting into crash and/or server memory leak.
Affected
36 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | spice | < spice 0.12.8-2.2 (bookworm) | spice 0.12.8-2.2 (bookworm) |
| spice_project | spice | — | — |
| spice_project | spice | — | — |
| spice_project | spice | — | — |
| spice_project | spice | — | — |
| spice_project | spice | — | — |
| spice_project | spice | — | — |
| spice_project | spice | — | — |
| spice_project | spice | — | — |
| spice_project | spice | — | — |
| spice_project | spice | — | — |
| spice_project | spice | — | — |
| spice_project | spice | — | — |
| spice_project | spice | — | — |
| spice_project | spice | — | — |
| spice_project | spice | — | — |
| spice_project | spice | — | — |
| spice_project | spice | — | — |
| spice_project | spice | — | — |
| spice_project | spice | — | — |
| spice_project | spice | — | — |
| spice_project | spice | — | — |
| spice_project | spice | — | — |
| spice_project | spice | — | — |
| spice_project | spice | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3pjw-h9v6-f5x8: spice versions though 0
ghsa_unreviewed·2022-05-14
CVE-2017-7506 [HIGH] CWE-119 GHSA-3pjw-h9v6-f5x8: spice versions though 0
spice versions though 0.13 are vulnerable to out-of-bounds memory access when processing specially crafted messages from authenticated attacker to the spice server resulting into crash and/or server memory leak.
OSV
CVE-2017-7506: spice versions though 0
osv·2017-07-18·CVSS 8.8
CVE-2017-7506 [HIGH] CVE-2017-7506: spice versions though 0
spice versions though 0.13 are vulnerable to out-of-bounds memory access when processing specially crafted messages from authenticated attacker to the spice server resulting into crash and/or server memory leak.
Ubuntu
Spice vulnerability
vendor_ubuntu·2017-07-19
CVE-2017-7506 Spice vulnerability
Title: Spice vulnerability
Summary: Spice could be made to crash or run programs if it received specially
crafted network traffic.
Frediano Ziglio discovered that Spice incorrectly handled certain invalid
monitor configurations. A remote attacker could use this issue to cause
Spice to crash, resulting in a denial of service, or possibly execute
arbitrary code.
Instructions: After a standard system update you need to restart qemu guests to make
all the necessary changes.
Red Hat
spice: Possible buffer overflow via invalid monitor configurations
vendor_redhat·2017-07-11·CVSS 8.8
CVE-2017-7506 [HIGH] CWE-681 spice: Possible buffer overflow via invalid monitor configurations
spice: Possible buffer overflow via invalid monitor configurations
spice versions though 0.13 are vulnerable to out-of-bounds memory access when processing specially crafted messages from authenticated attacker to the spice server resulting into crash and/or server memory leak.
A vulnerability was discovered in spice server's protocol handling. An authenticated attacker could send specially crafted messages to the spice server, causing out-of-bounds memory accesses, leading to parts of server memory being leaked or a crash.
Package: rhev-hypervisor (Red Hat Enterprise Linux 7) - Affected
Package: distribution (Red Hat Virtualization 4) - Affected
Debian
CVE-2017-7506: spice - spice versions though 0.13 are vulnerable to out-of-bounds memory access when pr...
vendor_debian·2017·CVSS 8.8
CVE-2017-7506 [HIGH] CVE-2017-7506: spice - spice versions though 0.13 are vulnerable to out-of-bounds memory access when pr...
spice versions though 0.13 are vulnerable to out-of-bounds memory access when processing specially crafted messages from authenticated attacker to the spice server resulting into crash and/or server memory leak.
Scope: local
bookworm: resolved (fixed in 0.12.8-2.2)
bullseye: resolved (fixed in 0.12.8-2.2)
forky: resolved (fixed in 0.12.8-2.2)
sid: resolved (fixed in 0.12.8-2.2)
trixie: resolved (fixed in 0.12.8-2.2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-7506 spice: Possible buffer overflow via invalid monitor configurations [fedora-all]
bugzilla·2017-07-11·CVSS 8.8
CVE-2017-7506 [HIGH] CVE-2017-7506 spice: Possible buffer overflow via invalid monitor configurations [fedora-all]
CVE-2017-7506 spice: Possible buffer overflow via invalid monitor configurations [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple su
Bugzilla
CVE-2017-7506 spice: Possible buffer overflow via invalid monitor configurations
bugzilla·2017-05-19·CVSS 8.8
CVE-2017-7506 [HIGH] CVE-2017-7506 spice: Possible buffer overflow via invalid monitor configurations
CVE-2017-7506 spice: Possible buffer overflow via invalid monitor configurations
For authenticated client it is possible to cause buffer overflow via sending invalid monitor configurations.
Proposed patch:
https://bugzilla.redhat.com/attachment.cgi?id=1279035
Product bug:
https://bugzilla.redhat.com/show_bug.cgi?id=1451021
Discussion:
Acknowledgments:
Name: Frediano Ziglio (Red Hat)
---
Yes, there are mainly 2 issues:
1) number of monitors bigger than the number of items. This will lead some copy from host to client (the number is capped to 64 by Qemu). This is similar to heartbleed bug;
2) integer overflow of buffer_size. If you get a negative number this will probably cause realloc to return NULL and the VM will be closed with an abort. Using very large buffer (>2GB, you are co
http://www.debian.org/security/2017/dsa-3907http://www.openwall.com/lists/oss-security/2017/07/14/1http://www.securityfocus.com/bid/99583https://access.redhat.com/errata/RHSA-2017:2471https://access.redhat.com/errata/RHSA-2018:3522https://bugzilla.redhat.com/show_bug.cgi?id=1452606http://www.debian.org/security/2017/dsa-3907http://www.openwall.com/lists/oss-security/2017/07/14/1http://www.securityfocus.com/bid/99583https://access.redhat.com/errata/RHSA-2017:2471https://access.redhat.com/errata/RHSA-2018:3522https://bugzilla.redhat.com/show_bug.cgi?id=1452606
2017-07-18
Published