Spice, versions 0.5.2 through 0.14.1, are vulnerable to an out-of-bounds read due to an off-by-one error in memslot_get_virt. This may lead to a denial of service, or, in the worst case, code-execution by unauthenticated attackers.
A product calculates or uses an incorrect maximum or minimum value that is 1 more, or 1 less, than the correct value.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Spice | Spice_project | 0.5.2 (including) | 0.14.1 (including) |
Red Hat Enterprise Linux 6 | RedHat | spice-server-0:0.12.4-16.el6_10.3 | * |
Red Hat Enterprise Linux 7 | RedHat | spice-0:0.14.0-6.el7_6.1 | * |
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | RedHat | redhat-release-virtualization-host-0:4.2-8.3.el7 | * |
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | RedHat | redhat-virtualization-host-0:4.2-20190219.0.el7_6 | * |
Spice | Ubuntu | bionic | * |
Spice | Ubuntu | cosmic | * |
Spice | Ubuntu | devel | * |
Spice | Ubuntu | trusty | * |
Spice | Ubuntu | upstream | * |
Spice | Ubuntu | xenial | * |