CVE-2016-9578: Input Validation
A vulnerability due to improper incoming messages validation was found in spice server that leads to remote VM crash via crafted message by unauthenticated attacker.
Product bug:
https://bugzilla.redhat.com/showbug.cgi?id=1399161
Other sources
A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An attacker able to connect to the SPICE server could send crafted messages which would cause the process to crash.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9578?
CVE-2016-9578 has been classified with a medium severity level due to the potential for remote denial of service.
How do I fix CVE-2016-9578?
To fix CVE-2016-9578, update the spice package to a version that is not affected, specifically versions 0.14.0-1.3+deb10u1, 0.14.3-2.1, or 0.15.1-1 for Debian, or version 0.13.90 for Red Hat.
Which systems are affected by CVE-2016-9578?
CVE-2016-9578 affects multiple versions of the spice package on Debian and Red Hat systems.
Can CVE-2016-9578 be exploited remotely?
Yes, CVE-2016-9578 can be exploited remotely by an unauthenticated attacker sending crafted messages.
What impact does CVE-2016-9578 have on systems?
The impact of CVE-2016-9578 is a potential crash of the virtual machine due to improper handling of incoming messages.