8.8
CVSSv3

CVE-2018-10893

Published: 11/09/2018 Updated: 12/02/2023
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Multiple integer overflow and buffer overflow issues were discovered in spice-client's handling of LZ compressed frames. A malicious server could cause the client to crash or, potentially, execute arbitrary code.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

spice project spice -

Vendor Advisories

Debian Bug report logs - #904161 spice-gtk: CVE-2018-10893: Insufficient encoding checks for LZ can cause different integer/buffer overflows Package: src:spice-gtk; Maintainer for src:spice-gtk is Liang Guo <guoliang@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 20 Jul 2018 22:18:02 UTC ...
Synopsis Moderate: spice-gtk security and bug fix update Type/Severity Security Advisory: Moderate Topic An update for spice-gtk, libgovirt, spice-vdagent, and virt-viewer is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Moderate ...
Synopsis Moderate: spice-gtk security update Type/Severity Security Advisory: Moderate Topic An update for spice-gtk is now available for Red Hat Enterprise Linux 6Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base score ...
Multiple integer overflow and buffer overflow issues were discovered in spice-client's handling of LZ compressed frames A malicious server could cause the client to crash or, potentially, execute arbitrary code ...
Multiple integer overflow and buffer overflow issues were discovered in spice-client's handling of LZ compressed frames A malicious server could cause the client to crash or, potentially, execute arbitrary code (CVE-2018-10893) ...
Multiple integer overflow and buffer overflow issues were discovered in spice-client's handling of LZ compressed frames A malicious server could cause the client to crash or, potentially, execute arbitrary code (CVE-2018-10893) ...
Multiple integer overflow and buffer overflow issues were discovered in spice-client's handling of LZ compressed frames A malicious server could cause the client to crash or, potentially, execute arbitrary code (CVE-2018-10893) ...
Multiple integer overflow and buffer overflow issues were discovered in spice-client's handling of LZ compressed frames A malicious server could cause the client to crash or, potentially, execute arbitrary code (CVE-2018-10893) ...
Multiple integer overflow and buffer overflow issues were discovered in spice-client's handling of LZ compressed frames A malicious server could cause the client to crash or, potentially, execute arbitrary code (CVE-2018-10893) ...