[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247974

 
 

909

 
 

194654

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2019-3813Date: (C)2019-06-17   (M)2023-12-22


Spice, versions 0.5.2 through 0.14.1, are vulnerable to an out-of-bounds read due to an off-by-one error in memslot_get_virt. This may lead to a denial of service, or, in the worst case, code-execution by unauthenticated attackers.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 7.5CVSS Score : 5.4
Exploit Score: 1.6Exploit Score: 5.5
Impact Score: 5.9Impact Score: 6.4
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: ADJACENT_NETWORKAccess Vector: ADJACENT_NETWORK
Attack Complexity: HIGHAccess Complexity: MEDIUM
Privileges Required: NONEAuthentication: NONE
User Interaction: NONEConfidentiality: PARTIAL
Scope: UNCHANGEDIntegrity: PARTIAL
Confidentiality: HIGHAvailability: PARTIAL
Integrity: HIGH 
Availability: HIGH 
  
Reference:
BID-106801
DSA-4375
GLSA-202007-30
RHSA-2019:0231
RHSA-2019:0232
RHSA-2019:0457
USN-3870-1
https://lists.debian.org/debian-lts-announce/2019/01/msg00026.html
https://bugzilla.redhat.com/show_bug.cgi?id=1665371

CPE    11
cpe:/o:debian:debian_linux:9.0
cpe:/o:debian:debian_linux:8.0
cpe:/o:canonical:ubuntu_linux:18.04::~~lts~~~
cpe:/o:redhat:enterprise_linux_server:6.0
...
CWE    1
CWE-193
OVAL    19
oval:org.secpod.oval:def:1801353
oval:org.secpod.oval:def:1801298
oval:org.secpod.oval:def:1801304
oval:org.secpod.oval:def:1801305
...

© SecPod Technologies