The (1) red_channel_pipes_add_type and (2) red_channel_pipes_add_empty_msg functions in server/red_channel.c in SPICE before 0.12.4 do not properly perform ring loops, which might allow remote attackers to cause a denial of service (reachable assertion and server exit) by triggering a network error.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Spice | Spice_project | * | 0.12.3 (including) |
Spice | Spice_project | 0.5.2 (including) | 0.5.2 (including) |
Spice | Spice_project | 0.5.3 (including) | 0.5.3 (including) |
Spice | Spice_project | 0.6.0 (including) | 0.6.0 (including) |
Spice | Spice_project | 0.6.1 (including) | 0.6.1 (including) |
Spice | Spice_project | 0.6.2 (including) | 0.6.2 (including) |
Spice | Spice_project | 0.6.3 (including) | 0.6.3 (including) |
Spice | Spice_project | 0.6.4 (including) | 0.6.4 (including) |
Spice | Spice_project | 0.7.0 (including) | 0.7.0 (including) |
Spice | Spice_project | 0.7.1 (including) | 0.7.1 (including) |
Spice | Spice_project | 0.7.2 (including) | 0.7.2 (including) |
Spice | Spice_project | 0.7.3 (including) | 0.7.3 (including) |
Spice | Spice_project | 0.8.0 (including) | 0.8.0 (including) |
Spice | Spice_project | 0.8.1 (including) | 0.8.1 (including) |
Spice | Spice_project | 0.8.2 (including) | 0.8.2 (including) |
Spice | Spice_project | 0.8.3 (including) | 0.8.3 (including) |
Spice | Spice_project | 0.9.0 (including) | 0.9.0 (including) |
Spice | Spice_project | 0.9.1 (including) | 0.9.1 (including) |
Spice | Spice_project | 0.10.0 (including) | 0.10.0 (including) |
Spice | Spice_project | 0.10.1 (including) | 0.10.1 (including) |
Spice | Spice_project | 0.11.0 (including) | 0.11.0 (including) |
Spice | Spice_project | 0.11.3 (including) | 0.11.3 (including) |
Spice | Spice_project | 0.12.0 (including) | 0.12.0 (including) |
Spice | Spice_project | 0.12.2 (including) | 0.12.2 (including) |
Red Hat Enterprise Linux 6 | RedHat | spice-server-0:0.12.0-12.el6_4.3 | * |
RHEV 3.X Hypervisor and Agents for RHEL-6 | RedHat | rhev-hypervisor6-0:6.4-20130912.1.el6_4 | * |
Spice | Ubuntu | devel | * |
Spice | Ubuntu | precise | * |
Spice | Ubuntu | quantal | * |
Spice | Ubuntu | raring | * |
Spice | Ubuntu | saucy | * |
Spice | Ubuntu | trusty | * |
Spice | Ubuntu | upstream | * |
Spice | Ubuntu | utopic | * |
Spice | Ubuntu | vivid | * |
Spice | Ubuntu | wily | * |
Spice | Ubuntu | xenial | * |
Spice | Ubuntu | yakkety | * |
Spice | Ubuntu | zesty | * |