CVE-2018-10893: Integer Overflow
A flaw was found in spice-client. An improper check on LZ images sent by the server could lead to an integer/buffer overflows on the client.
References: https://bugzilla.redhat.com/showbug.cgi?id=1594904
Other sources
Multiple integer overflow and buffer overflow issues were discovered in spice-client's handling of LZ compressed frames. A malicious server could cause the client to crash or, potentially, execute arbitrary code.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-10893?
CVE-2018-10893 is a vulnerability in spice-client's handling of LZ compressed frames that can allow a malicious server to crash the client or execute arbitrary code.
How severe is CVE-2018-10893?
CVE-2018-10893 has a severity rating of 8.8 out of 10, indicating a high severity.
What software is affected by CVE-2018-10893?
The Spice Project Spice software is affected by CVE-2018-10893.
What is the impact of CVE-2018-10893?
CVE-2018-10893 can cause a client to crash or potentially execute arbitrary code if exploited by a malicious server.
Are there any references for CVE-2018-10893?
You can find more information about CVE-2018-10893 at the following references: [Bugzilla 1594904](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1594904), [Bugzilla 1598236](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1598236), [Bugzilla 1598235](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1598235).