5
CVSSv2

CVE-2016-9578

Published: 27/07/2018 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

A vulnerability exists in SPICE prior to 0.13.90 in the server's protocol handling. An attacker able to connect to the SPICE server could send crafted messages which would cause the process to crash.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

spice project spice

redhat enterprise linux desktop 7.0

redhat enterprise linux workstation 7.0

redhat enterprise linux server 7.0

debian debian linux 8.0

redhat enterprise linux desktop 6.0

redhat enterprise linux server 6.0

redhat enterprise linux workstation 6.0

redhat enterprise linux server aus 7.3

redhat enterprise linux server aus 7.4

redhat enterprise linux server eus 7.3

redhat enterprise linux server eus 7.4

redhat enterprise linux server eus 7.5

Vendor Advisories

Debian Bug report logs - #854336 CVE-2016-9577 CVE-2016-9578 Package: src:spice; Maintainer for src:spice is Liang Guo <guoliang@debianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Mon, 6 Feb 2017 07:36:01 UTC Severity: grave Tags: patch, security Found in versions spice/0125-1, spice/0128-2 Fix ...
Spice could be made to crash or run programs if it received specially crafted network traffic ...
Several vulnerabilities were discovered in spice, a SPICE protocol client and server library The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2016-9577 Frediano Ziglio of Red Hat discovered a buffer overflow vulnerability in the main_channel_alloc_msg_rcv_buf function An authenticated attacker c ...
Synopsis Moderate: redhat-virtualization-host security and bug fix update Type/Severity Security Advisory: Moderate Topic An update for imgbased, redhat-release-virtualization-host, and redhat-virtualization-host is now available for RHEV 4X, RHEV-H, and Agents for RHEL-7Red Hat Product Security has rated ...
Synopsis Moderate: rhevm-appliance security and bug fix update Type/Severity Security Advisory: Moderate Topic An update for rhevm-appliance is now available for RHEV 4X RHEV-H and Agents for RHEL-7Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerabili ...
Synopsis Moderate: spice-server security update Type/Severity Security Advisory: Moderate Topic An update for spice-server is now available for Red Hat Enterprise Linux 6Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base ...
Synopsis Moderate: spice security update Type/Severity Security Advisory: Moderate Topic An update for spice is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base score, which ...
A vulnerability was discovered in SPICE in the server's protocol handling An attacker able to connect to the SPICE server could send crafted messages which would cause the process to crash ...