Input validation error in SPICE - CVE-2016-9578
Published: July 27, 2018 / Updated: July 17, 2020
Vulnerability identifier: #VU31250
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-9578
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An attacker able to connect to the SPICE server could send crafted messages which would cause the process to crash.
Affected software
SPICE
spice (Alpine package)
spice-server (Red Hat package)
spice (Red Hat package)
spice
rhevm-appliance (Red Hat package)
Red Hat Virtualization
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Server - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux Server - AUS
SUSE Linux
Fedora
Opensuse
spice (Alpine package)
spice-server (Red Hat package)
spice (Red Hat package)
spice
rhevm-appliance (Red Hat package)
Red Hat Virtualization
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Server - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux Server - AUS
SUSE Linux
Fedora
Opensuse
How to mitigate CVE-2016-9578
Install update from vendor's website.
SPICE - update to 0.13.90
spice (Alpine package) - update to 0.12.8-r3
spice-server (Red Hat package) - update to 0.12.4-13.el6_8.2
spice (Red Hat package) - update to 0.12.4-20.el7_3
spice - addressed in versions 0.12.8-2.fc24, 0.13.3-2.fc25
rhevm-appliance (Red Hat package) - update to 4.0.20170307.0-1.el7ev
spice (Alpine package) - update to 0.12.8-r3
spice-server (Red Hat package) - update to 0.12.4-13.el6_8.2
spice (Red Hat package) - update to 0.12.4-20.el7_3
spice - addressed in versions 0.12.8-2.fc24, 0.13.3-2.fc25
rhevm-appliance (Red Hat package) - update to 4.0.20170307.0-1.el7ev
External References
- http://rhn.redhat.com/errata/RHSA-2017-0253.html
- http://rhn.redhat.com/errata/RHSA-2017-0549.html
- http://www.securityfocus.com/bid/96118
- https://access.redhat.com/errata/RHSA-2017:0254
- https://access.redhat.com/errata/RHSA-2017:0552
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-9578
- https://www.debian.org/security/2017/dsa-3790
Related Security Bulletins
- Multiple vulnerabilities in SPICE SPICE
- OpenSUSE Linux update for spice
- OpenSUSE Linux update for spice
- SUSE Linux update for spice
- SUSE Linux update for spice
- SUSE Linux update for spice
- SUSE Linux update for spice
- Input validation error in spice (Alpine package)
- Fedora 25 update for spice
- Fedora 24 update for spice
- Red Hat Enterprise Linux 7 update for spice
- Red Hat Enterprise Linux 6 update for spice-server
- RHEV 4 update for rhevm-appliance