First published: Wed Jul 04 2018(Updated: )
Multiple integer overflow and buffer overflow issues were discovered in spice-client's handling of LZ compressed frames. A malicious server could cause the client to crash or, potentially, execute arbitrary code.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Spice Project Spice |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-10893 is a vulnerability in spice-client's handling of LZ compressed frames that can allow a malicious server to crash the client or execute arbitrary code.
CVE-2018-10893 has a severity rating of 8.8 out of 10, indicating a high severity.
The Spice Project Spice software is affected by CVE-2018-10893.
CVE-2018-10893 can cause a client to crash or potentially execute arbitrary code if exploited by a malicious server.
You can find more information about CVE-2018-10893 at the following references: [Bugzilla 1594904](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1594904), [Bugzilla 1598236](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1598236), [Bugzilla 1598235](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1598235).