CVE-2018-10873 PUBLISHED

A vulnerability was discovered in SPICE before version 0.14.1 where the generated code used for demarshalling messages lacked sufficient bounds checks. A malicious client or server, after authentication, could send specially crafted messages to its peer which would result in a crash or, potentially, other impacts.

EPSS 1.21% · 78.9th percentile

Risk Scores

EPSS Score
1.21%
78.9th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSspice-protocol0, 0.12.7-1, 0.12.10-1
Ubuntu:14.04:LTSspice0.12.4-0nocelt2, 0.12.4-0nocelt2ubuntu1, 0.12.4-0nocelt2ubuntu1.1
Ubuntu:18.04:LTSspice-gtk0.34-1.1build1, 0.34-1.1, 0.33-3.3
Ubuntu:16.04:LTSspice-gtk0, 0.28-1ubuntu1, 0.29-1
Ubuntu:18.04:LTSspice0.14.0-1ubuntu2, 0.14.0-1ubuntu2.1, 0.14.0-1ubuntu1

Timeline

References

Open in Interactive Console →