cbcvebase.
CVE-2018-10873
published 2018-08-17

CVE-2018-10873: A vulnerability was discovered in SPICE before version 0.14.1 where the generated code used for demarshalling messages lacked sufficient bounds checks. A…

high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
A vulnerability was discovered in SPICE before version 0.14.1 where the generated code used for demarshalling messages lacked sufficient bounds checks. A malicious client or server, after authentication, could send specially crafted messages to its peer which would result in a crash or, potentially, other impacts.

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debianspice< spice 0.14.0-1.1 (bookworm)spice 0.14.0-1.1 (bookworm)
debianspice-gtk< spice 0.14.0-1.1 (bookworm)spice 0.14.0-1.1 (bookworm)
redhatenterprise_linux_desktop
redhatenterprise_linux_desktop
redhatenterprise_linux_server
redhatenterprise_linux_server
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_tus
redhatenterprise_linux_workstation
redhatenterprise_linux_workstation
redhatvirtualization
redhatvirtualization_host
spice-gtk_projectspice-gtk>= 0 < 0.35-10.35-1
spice-gtk_projectspice-gtk>= 0 < 0.35-10.35-1
spice-gtk_projectspice-gtk>= 0 < 0.35-10.35-1
spice-gtk_projectspice-gtk>= 0 < 0.35-10.35-1
spice_projectspice< 0.14.10.14.1
spice_projectspice>= 0 < 0.14.0-1.10.14.0-1.1

CVSS provenance

nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH