← Back

CVE-2013-4130

nvd nist
Published: Aug 20, 2013Modified: Apr 29, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:N/I:N/A:P
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

The (1) red_channel_pipes_add_type and (2) red_channel_pipes_add_empty_msg functions in server/red_channel.c in SPICE before 0.12.4 do not properly perform ring loops, which might allow remote attackers to cause a denial of service (reachable assertion and server exit) by triggering a network error.

Affected (25)

1 product
Spice
1 product
Ubuntu Linux
Configuration A
24 vulnerable
Vulnerable SoftwareAffected Versions
Spice Project
Up to 0.12.3
Version 0.10.0
Version 0.10.1
Version 0.11.0
Version 0.11.3
Version 0.12.0
Version 0.12.2
Version 0.5.2
Version 0.5.3
Version 0.6.0
Version 0.6.1
Version 0.6.2
Version 0.6.3
Version 0.6.4
Version 0.7.0
Version 0.7.1
Version 0.7.2
Version 0.7.3
Version 0.8.0
Version 0.8.1
Version 0.8.2
Version 0.8.3
Version 0.9.0
Version 0.9.1
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 13.04

Related CWEs

References (12)

Source: secalert@redhat.com
Source: secalert@redhat.com
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.