CVE-2016-9577 PUBLISHED

A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An authenticated attacker could send crafted messages to the SPICE server causing a heap overflow leading to a crash or possible code execution.

EPSS 3.67% · 87.8th percentile

Risk Scores

EPSS Score
3.67%
87.8th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSspice0, 0.12.5-1.1ubuntu2, 0.12.6-4
Ubuntu:14.04:LTSspice0.12.4-0nocelt2, 0.12.4-0nocelt2ubuntu1, 0

Timeline

References

Open in Interactive Console →