VDB

ALINUX2-SA-2019%3A0068

ALINUX2-SA-2019%3A0068 PUBLISHED CVSS 7.599999904632568 HIGH

Package updates are available for Alibaba Cloud Linux 2.1903 that fix the following vulnerabilities: CVE-2018-10893: Multiple integer overflow and buffer overflow issues were discovered in spice-client's handling of LZ compressed frames. A malicious server could cause the client to crash or, potentially, execute arbitrary code.

Risk Scores

CVSS 3.0
7.599999904632568
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L

Affected Products

VendorProductVersions
Alibaba Cloudvirt-viewer
Alibaba Cloudspice-vdagent
Alibaba Cloudlibgovirt
Alibaba Cloudspice-gtk

Timeline

  • Oct 9, 2019 CVE Published
  • Oct 9, 2019 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›