All errata/c7.1/ALT-PU-2018-2432-1
ALT-PU-2018-2432-1

Package update SPICE in branch c7.1

Version0.12.7-alt0.M70C.1
Published2018-10-08
Max severityHIGH
Severity:

Closed issues (3)

CVE-2013-4130
MEDIUM5.0

The (1) red_channel_pipes_add_type and (2) red_channel_pipes_add_empty_msg functions in server/red_channel.c in SPICE before 0.12.4 do not properly perform ring loops, which might allow remote attackers to cause a denial of service (reachable assertion and server exit) by triggering a network error.

Published: 2013-08-20Modified: 2026-04-29
CVSS 2.0MEDIUM 5.0
CVSS:2.0/AV:N/AC:L/Au:N/C:N/I:N/A:P