5
CVSSv2

CVE-2013-4282

Published: 02/11/2013 Updated: 13/02/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Stack-based buffer overflow in the reds_handle_ticket function in server/reds.c in SPICE 0.12.0 allows remote malicious users to cause a denial of service (crash) via a long password in a SPICE ticket.

Vulnerable Product Search on Vulmon Subscribe to Product

spice project spice 0.12.0

redhat enterprise linux 6.0

redhat enterprise virtualization 3.0

redhat enterprise linux 5

Vendor Advisories

SPICE could be made to crash if it received specially crafted network traffic ...
Debian Bug report logs - #717030 spice: CVE-2013-4130 Package: spice; Maintainer for spice is Liang Guo <guoliang@debianorg>; Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Tue, 16 Jul 2013 07:42:02 UTC Severity: grave Tags: security Found in version 0110-1 Fixed in versions spice/0124-0nocelt1, spice/0 ...
Debian Bug report logs - #728314 spice: CVE-2013-4282: stack buffer overflow in reds_handle_ticket() function Package: spice; Maintainer for spice is Liang Guo <guoliang@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 30 Oct 2013 15:00:02 UTC Severity: grave Tags: fixed-upstream, patch, ...
Synopsis Important: rhev-hypervisor6 security and bug fix update Type/Severity Security Advisory: Important Topic An updated rhev-hypervisor6 package that fixes one security issue andvarious bugs is now availableThe Red Hat Security Response Team has rated this update as havingimportant security impact A ...
Synopsis Important: spice-server security update Type/Severity Security Advisory: Important Topic An updated spice-server package that fixes one security issue is nowavailable for Red Hat Enterprise Linux 6The Red Hat Security Response Team has rated this update as havingimportant security impact A Common ...
Synopsis Important: qspice security update Type/Severity Security Advisory: Important Topic Updated qspice packages that fix one security issue are now available forRed Hat Enterprise Linux 5The Red Hat Security Response Team has rated this update as havingimportant security impact A Common Vulnerability ...
Multiple vulnerabilities have been found in spice, a SPICE protocol client and server library The Common Vulnerabilities and Exposures project identifies the following issues: CVE-2013-4130 David Gibson of Red Hat discovered that SPICE incorrectly handled certain network errors A remote user able to initiate a SPICE connection to an applic ...