cbcvebase.
CVE-2019-3813
published 2019-02-04

CVE-2019-3813: Spice, versions 0.5.2 through 0.14.1, are vulnerable to an out-of-bounds read due to an off-by-one error in memslot_get_virt. This may lead to a denial of…

high7.5CVSS 3.1
AVAACHPRNUINSUCHIHAH
Spice, versions 0.5.2 through 0.14.1, are vulnerable to an out-of-bounds read due to an off-by-one error in memslot_get_virt. This may lead to a denial of service, or, in the worst case, code-execution by unauthenticated attackers.

Affected

22 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debianspice< spice 0.14.0-1.3 (bookworm)spice 0.14.0-1.3 (bookworm)
red_hat_incspice
redhatenterprise_linux_desktop
redhatenterprise_linux_desktop
redhatenterprise_linux_server
redhatenterprise_linux_server
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_tus
redhatenterprise_linux_workstation
redhatenterprise_linux_workstation
spice_projectspice>= 0 < 0.14.0-1.30.14.0-1.3
spice_projectspice>= 0 < 0.14.0-1.30.14.0-1.3
spice_projectspice>= 0 < 0.14.0-1.30.14.0-1.3
spice_projectspice>= 0 < 0.14.0-1.30.14.0-1.3
spice_projectspice0.5.2 – 0.14.1

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
osv7.5HIGH