Off-by-one in SPICE - CVE-2019-3813

 

Off-by-one in SPICE - CVE-2019-3813

Published: January 31, 2019 / Updated: February 11, 2019


Vulnerability identifier: #VU17324
CSH Severity: Medium
CVSS v4: 7.5 [CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-3813
CWE-ID: CWE-193
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an adjacent authenticated attacker to cause DoS condition.

The vulnerability exists due to an off-by-one error in memslot_get_virt. An adjacent can trigger out-of-bounds read and cause the program to crash if it received specially crafted network traffic. In case the attacker in unauthenticated it's possible to execute arbitrary code.


Affected software

SPICE
Arch Linux
Gentoo Linux
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Opensuse
Fedora
spice (Debian package)
spice (Alpine package)
spice
Red Hat Virtualization
Red Hat Virtualization Host

How to mitigate CVE-2019-3813

Update to version 0.14.2.

SPICE - update to 0.14.2
spice (Debian package) - update to 0.12.8-2.1+deb9u3
spice (Alpine package) - update to 0.13.3-r4
spice - addressed in versions 0.14.0-5.fc28, 0.14.1-2.fc29

External References

Related Security Bulletins