Description
A flaw was found in the way spice-client processed certain messages sent from the server. An attacker, having control of malicious spice-server, could use this flaw to crash the client or execute arbitrary code with permissions of the user running the client. spice-gtk versions through 0.34 are believed to be vulnerable.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-3769 | A flaw was found in the way spice-client processed certain messages sent from the server. An attacker, having control of malicious spice-server, could use this flaw to crash the client or execute arbitrary code with permissions of the user running the client. spice-gtk versions through 0.34 are believed to be vulnerable. |
Ubuntu USN |
USN-3659-1 | Spice vulnerability |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-05T18:28:16.674Z
Reserved: 2017-08-01T00:00:00.000Z
Link: CVE-2017-12194
No data.
Status : Modified
Published: 2018-03-14T21:29:00.207
Modified: 2024-11-21T03:09:01.710
Link: CVE-2017-12194
OpenCVE Enrichment
No data.
EUVD
Ubuntu USN