CVE-2016-9578
Summary
| CVE | CVE-2016-9578 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-07-27 21:29:00 UTC |
| Updated | 2023-11-07 02:37:00 UTC |
| Description | A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An attacker able to connect to the SPICE server could send crafted messages which would cause the process to crash. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Debian -- Security Information -- DSA-3790-1 spice |
DEBIAN |
www.debian.org |
Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| Spice CVE-2016-9578 Remote Denial of Service Vulnerability |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| Red Hat Customer Portal |
REDHAT |
rhn.redhat.com |
Third Party Advisory |
| 1399566 – (CVE-2016-9578) CVE-2016-9578 spice: Remote DoS via crafted message |
CONFIRM |
bugzilla.redhat.com |
Issue Tracking, Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
rhn.redhat.com |
Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 378110 Virtuozzo Linux Security Update for spice-server-devel (VZLSA-2017:0253)
- 378261 Virtuozzo Linux Security Update for spice-server-devel (VZLSA-2017:0254)
- 500646 Alpine Linux Security Update for spice
- 504413 Alpine Linux Security Update for spice