Spice-Gtk Project Spice-Gtk vulnerabilities

7 known vulnerabilities affecting spice-gtk_project/spice-gtk.

Total CVEs
7
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH2MEDIUM4

Vulnerabilities

Page 1 of 1
CVE-2020-14355MEDIUMCVSS 6.6≥ 0, < 0.39-12020-10-07
CVE-2020-14355 [MEDIUM] CVE-2020-14355: Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0 Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk) and server are affected by these flaws. These flaws allow a malicious client or server to send specially crafted messages that, when processed
osv
CVE-2018-10893HIGHCVSS 8.8≥ 0, < 0.37-12018-09-11
CVE-2018-10893 [HIGH] CVE-2018-10893: Multiple integer overflow and buffer overflow issues were discovered in spice-client's handling of LZ compressed frames Multiple integer overflow and buffer overflow issues were discovered in spice-client's handling of LZ compressed frames. A malicious server could cause the client to crash or, potentially, execute arbitrary code.
osv
CVE-2018-10873HIGHCVSS 8.8≥ 0, < 0.35-12018-08-17
CVE-2018-10873 [HIGH] CVE-2018-10873: A vulnerability was discovered in SPICE before version 0 A vulnerability was discovered in SPICE before version 0.14.1 where the generated code used for demarshalling messages lacked sufficient bounds checks. A malicious client or server, after authentication, could send specially crafted messages to its peer which would result in a crash or, potentially, other impacts.
osv
CVE-2017-12194CRITICALCVSS 9.8≤ 0.342018-03-14
CVE-2017-12194 [CRITICAL] CWE-121 CVE-2017-12194: A flaw was found in the way spice-client processed certain messages sent from the server. An attacke A flaw was found in the way spice-client processed certain messages sent from the server. An attacker, having control of malicious spice-server, could use this flaw to crash the client or execute arbitrary code with permissions of the user running the client. spice-gtk versions through 0.34 are believed to be vulnerable.
nvdosv
CVE-2016-3066MEDIUMCVSS 6.5v0.1.0v0.2+35 more2017-06-06
CVE-2016-3066 [MEDIUM] CWE-200 CVE-2016-3066: The spice-gtk widget allows remote authenticated users to obtain information from the host clipboard The spice-gtk widget allows remote authenticated users to obtain information from the host clipboard.
nvd
CVE-2013-4324MEDIUMCVSS 4.6v0.142013-10-03
CVE-2013-4324 [MEDIUM] CVE-2013-4324: spice-gtk 0.14, and possibly other versions, invokes the polkit authority using the insecure polkit_ spice-gtk 0.14, and possibly other versions, invokes the polkit authority using the insecure polkit_unix_process_new API function, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.
nvdosv
CVE-2012-4425MEDIUMCVSS 6.9PoC≥ 0, < 0.12-52012-09-18
CVE-2012-4425 [MEDIUM] CVE-2012-4425: libgio, when used in setuid or other privileged programs in spice-gtk and possibly other products, allows local users to gain privileges and execute a libgio, when used in setuid or other privileged programs in spice-gtk and possibly other products, allows local users to gain privileges and execute arbitrary code via the DBUS_SYSTEM_BUS_ADDRESS environment variable. NOTE: it could be argued that this is a vulnerability in the applications that do not cleanse
osv