CVE Vulnerabilities

CVE-2013-4130

Published: Aug 20, 2013 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
4.3 MODERATE
AV:A/AC:H/Au:S/C:N/I:N/A:C
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The (1) red_channel_pipes_add_type and (2) red_channel_pipes_add_empty_msg functions in server/red_channel.c in SPICE before 0.12.4 do not properly perform ring loops, which might allow remote attackers to cause a denial of service (reachable assertion and server exit) by triggering a network error.

Affected Software

NameVendorStart VersionEnd Version
SpiceSpice_project*0.12.3 (including)
SpiceSpice_project0.5.2 (including)0.5.2 (including)
SpiceSpice_project0.5.3 (including)0.5.3 (including)
SpiceSpice_project0.6.0 (including)0.6.0 (including)
SpiceSpice_project0.6.1 (including)0.6.1 (including)
SpiceSpice_project0.6.2 (including)0.6.2 (including)
SpiceSpice_project0.6.3 (including)0.6.3 (including)
SpiceSpice_project0.6.4 (including)0.6.4 (including)
SpiceSpice_project0.7.0 (including)0.7.0 (including)
SpiceSpice_project0.7.1 (including)0.7.1 (including)
SpiceSpice_project0.7.2 (including)0.7.2 (including)
SpiceSpice_project0.7.3 (including)0.7.3 (including)
SpiceSpice_project0.8.0 (including)0.8.0 (including)
SpiceSpice_project0.8.1 (including)0.8.1 (including)
SpiceSpice_project0.8.2 (including)0.8.2 (including)
SpiceSpice_project0.8.3 (including)0.8.3 (including)
SpiceSpice_project0.9.0 (including)0.9.0 (including)
SpiceSpice_project0.9.1 (including)0.9.1 (including)
SpiceSpice_project0.10.0 (including)0.10.0 (including)
SpiceSpice_project0.10.1 (including)0.10.1 (including)
SpiceSpice_project0.11.0 (including)0.11.0 (including)
SpiceSpice_project0.11.3 (including)0.11.3 (including)
SpiceSpice_project0.12.0 (including)0.12.0 (including)
SpiceSpice_project0.12.2 (including)0.12.2 (including)
Red Hat Enterprise Linux 6RedHatspice-server-0:0.12.0-12.el6_4.3*
RHEV 3.X Hypervisor and Agents for RHEL-6RedHatrhev-hypervisor6-0:6.4-20130912.1.el6_4*
SpiceUbuntudevel*
SpiceUbuntuesm-infra-legacy/trusty*
SpiceUbuntuesm-infra/xenial*
SpiceUbuntuprecise*
SpiceUbuntuquantal*
SpiceUbunturaring*
SpiceUbuntusaucy*
SpiceUbuntutrusty*
SpiceUbuntutrusty/esm*
SpiceUbuntuupstream*
SpiceUbuntuutopic*
SpiceUbuntuvivid*
SpiceUbuntuwily*
SpiceUbuntuxenial*
SpiceUbuntuyakkety*
SpiceUbuntuzesty*

References