CVE-2019-3813
published 2019-02-04CVE-2019-3813: Spice, versions 0.5.2 through 0.14.1, are vulnerable to an out-of-bounds read due to an off-by-one error in memslot_get_virt. This may lead to a denial of…
PriorityP337high7.5CVSS 3.1
AVAACHPRNUINSUCHIHAH
EPSS
1.21%
64.9th percentile
Spice, versions 0.5.2 through 0.14.1, are vulnerable to an out-of-bounds read due to an off-by-one error in memslot_get_virt. This may lead to a denial of service, or, in the worst case, code-execution by unauthenticated attackers.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | spice | < spice 0.14.0-1.3 (bookworm) | spice 0.14.0-1.3 (bookworm) |
| red_hat_inc | spice | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
| spice_project | spice | >= 0 < 0.14.0-1.3 | 0.14.0-1.3 |
| spice_project | spice | >= 0 < 0.14.0-1.3 | 0.14.0-1.3 |
| spice_project | spice | >= 0 < 0.14.0-1.3 | 0.14.0-1.3 |
| spice_project | spice | >= 0 < 0.14.0-1.3 | 0.14.0-1.3 |
| spice_project | spice | 0.5.2 – 0.14.1 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.05.4MEDIUMAV:A/AC:M/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Spice vulnerability
vendor_ubuntu·2019-01-28
CVE-2019-3813 Spice vulnerability
Title: Spice vulnerability
Summary: Spice could be made to crash or run programs if it received specially
crafted network traffic.
Christophe Fergeau discovered that Spice incorrectly handled memory. A
remote attacker could use this to cause Spice to crash, resulting in a
denial of service, or possibly execute arbitrary code.
Instructions: After a standard system update you need to restart qemu guests to make all
the necessary changes.
Red Hat
spice: Off-by-one error in array access in spice/server/memslot.c
vendor_redhat·2019-01-28·CVSS 7.5
CVE-2019-3813 [HIGH] CWE-193 spice: Off-by-one error in array access in spice/server/memslot.c
spice: Off-by-one error in array access in spice/server/memslot.c
Spice, versions 0.5.2 through 0.14.1, are vulnerable to an out-of-bounds read due to an off-by-one error in memslot_get_virt. This may lead to a denial of service, or, in the worst case, code-execution by unauthenticated attackers.
Spice, versions 0.5.2 through 0.14.1, are vulnerable to an out-of-bounds read due to an off-by-one error in memslot_get_virt. This may lead to a denial of service, or, in the worst case, code-execution by unauthenticated attackers.
Package: spice (Red Hat Enterprise Linux 8) - Not affected
Debian
CVE-2019-3813: spice - Spice, versions 0.5.2 through 0.14.1, are vulnerable to an out-of-bounds read du...
vendor_debian·2019·CVSS 7.5
CVE-2019-3813 [HIGH] CVE-2019-3813: spice - Spice, versions 0.5.2 through 0.14.1, are vulnerable to an out-of-bounds read du...
Spice, versions 0.5.2 through 0.14.1, are vulnerable to an out-of-bounds read due to an off-by-one error in memslot_get_virt. This may lead to a denial of service, or, in the worst case, code-execution by unauthenticated attackers.
Scope: local
bookworm: resolved (fixed in 0.14.0-1.3)
bullseye: resolved (fixed in 0.14.0-1.3)
forky: resolved (fixed in 0.14.0-1.3)
sid: resolved (fixed in 0.14.0-1.3)
trixie: resolved (fixed in 0.14.0-1.3)
GHSA
GHSA-j8r4-w4xh-mcv3: Spice, versions 0
ghsa_unreviewed·2022-04-30
CVE-2019-3813 [HIGH] CWE-193 GHSA-j8r4-w4xh-mcv3: Spice, versions 0
Spice, versions 0.5.2 through 0.14.1, are vulnerable to an out-of-bounds read due to an off-by-one error in memslot_get_virt. This may lead to a denial of service, or, in the worst case, code-execution by unauthenticated attackers.
OSV
CVE-2019-3813: Spice, versions 0
osv·2019-02-04·CVSS 7.5
CVE-2019-3813 [HIGH] CVE-2019-3813: Spice, versions 0
Spice, versions 0.5.2 through 0.14.1, are vulnerable to an out-of-bounds read due to an off-by-one error in memslot_get_virt. This may lead to a denial of service, or, in the worst case, code-execution by unauthenticated attackers.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-3813 spice: Off-by-one error in array access in spice/server/memslot.c [fedora-all]
bugzilla·2019-01-28·CVSS 7.5
CVE-2019-3813 [HIGH] CVE-2019-3813 spice: Off-by-one error in array access in spice/server/memslot.c [fedora-all]
CVE-2019-3813 spice: Off-by-one error in array access in spice/server/memslot.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple sup
Bugzilla
CVE-2019-3813 spice: Off-by-one error in array access in spice/server/memslot.c
bugzilla·2019-01-11·CVSS 7.5
CVE-2019-3813 [HIGH] CVE-2019-3813 spice: Off-by-one error in array access in spice/server/memslot.c
CVE-2019-3813 spice: Off-by-one error in array access in spice/server/memslot.c
An off-by-one error was found in spice when accessing arrays. A malicious guest user can use this for a host denial of service.
Discussion:
Does look like it can change program control flow assuming checks can be bypassed, an attacker can control the heap information past the end of the buffer, etc. memslot_get_virt looks to return chunks of memory back to callers that are then cast into different structs and used. Thus, information leaks may be possible, lots of other super-undefined behavior could potentially occur (i.e. code execution)
```
│1426 qxl = (QXLCursor *)memslot_get_virt(slots, addr, sizeof(*qxl), group_id, &error); │
>│1427 if (error) { │
│1428 return false; │
│1429 } │
│1430 │
│1431 red->head
http://www.securityfocus.com/bid/106801https://access.redhat.com/errata/RHSA-2019:0231https://access.redhat.com/errata/RHSA-2019:0232https://access.redhat.com/errata/RHSA-2019:0457https://bugzilla.redhat.com/show_bug.cgi?id=1665371https://lists.debian.org/debian-lts-announce/2019/01/msg00026.htmlhttps://security.gentoo.org/glsa/202007-30https://usn.ubuntu.com/3870-1/https://www.debian.org/security/2019/dsa-4375http://www.securityfocus.com/bid/106801https://access.redhat.com/errata/RHSA-2019:0231https://access.redhat.com/errata/RHSA-2019:0232https://access.redhat.com/errata/RHSA-2019:0457https://bugzilla.redhat.com/show_bug.cgi?id=1665371https://lists.debian.org/debian-lts-announce/2019/01/msg00026.htmlhttps://security.gentoo.org/glsa/202007-30https://usn.ubuntu.com/3870-1/https://www.debian.org/security/2019/dsa-4375
2019-02-04
Published