← Back

CVE-2017-7506

nvd nist
Published: Jul 18, 2017Modified: May 13, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

spice versions though 0.13 are vulnerable to out-of-bounds memory access when processing specially crafted messages from authenticated attacker to the spice server resulting into crash and/or server memory leak.

Affected (30)

Products: Spice Project: Spice
1 product
Spice
Configuration A
30 vulnerable
Vulnerable SoftwareAffected Versions
Spice Project
Version 0.10.0
Version 0.10.1
Version 0.11.0
Version 0.11.3
Version 0.12.0
Version 0.12.2
Version 0.12.3
Version 0.12.4
Version 0.12.5
Version 0.12.6
Version 0.12.7
Version 0.12.8
Version 0.13.0
Version 0.5.2
Version 0.5.3
Version 0.6.0
Version 0.6.1
Version 0.6.2
Version 0.6.3
Version 0.6.4
Version 0.7.0
Version 0.7.1
Version 0.7.2
Version 0.7.3
Version 0.8.0
Version 0.8.1
Version 0.8.2
Version 0.8.3
Version 0.9.0
Version 0.9.1

References (12)

Source: secalert@redhat.com
Mailing ListThird Party Advisory
Source: secalert@redhat.com
Third Party AdvisoryVDB Entry
Source: secalert@redhat.com
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory

Timeline

No history available yet.