CVE-2018-10873
A vulnerability was discovered in SPICE before version 0.14.1 where the generated code used for demarshalling messages lacked sufficient bounds checks.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.93%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A vulnerability was discovered in SPICE before version 0.14.1 where the generated code used for demarshalling messages lacked sufficient bounds checks. A malicious client or server, after authentication, could send specially crafted messages to its peer which would result in a crash or, potentially, other impacts.
- CVSS 3.0
- 8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 3.93% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119, CWE-20
- Affected
- spice project/spice · debian/debian linux · canonical/ubuntu linux · redhat/virtualization · redhat/virtualization host · redhat/enterprise linux desktop · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux server eus · redhat/enterprise linux server tus · redhat/enterprise linux workstation
- Source
- secalert@redhat.com
References
- http://www.securityfocus.com/bid/105152Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:2731Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2732Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3470Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10873Issue Tracking, Third Party Advisory
- https://gitlab.freedesktop.org/spice/spice-common/commit/bb15d4815ab586b4c4a20f4a565970a44824c42cPatch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/08/msg00035.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/08/msg00037.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/08/msg00038.htmlMailing List, Third Party Advisory
- https://usn.ubuntu.com/3751-1/Third Party Advisory
- https://www.debian.org/security/2018/dsa-4319Third Party Advisory
- http://www.securityfocus.com/bid/105152Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:2731Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2732Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3470Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10873Issue Tracking, Third Party Advisory
- https://gitlab.freedesktop.org/spice/spice-common/commit/bb15d4815ab586b4c4a20f4a565970a44824c42cPatch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/08/msg00035.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/08/msg00037.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/08/msg00038.htmlMailing List, Third Party Advisory
- https://usn.ubuntu.com/3751-1/Third Party Advisory
- https://www.debian.org/security/2018/dsa-4319Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.