Buffer overflow in SPICE - CVE-2016-9577

 

Buffer overflow in SPICE - CVE-2016-9577

Published: July 27, 2018 / Updated: July 17, 2020


Vulnerability identifier: #VU31251
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-9577
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated user to execute arbitrary code.

A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An authenticated attacker could send crafted messages to the SPICE server causing a heap overflow leading to a crash or possible code execution.


Affected software

SPICE
spice (Alpine package)
spice-server (Red Hat package)
spice (Red Hat package)
spice
rhevm-appliance (Red Hat package)
Red Hat Virtualization
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Server - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux Server - AUS
SUSE Linux
Fedora
Opensuse

How to mitigate CVE-2016-9577

Install update from vendor's website.

SPICE - update to 0.13.90
spice (Alpine package) - update to 0.12.8-r3
spice-server (Red Hat package) - update to 0.12.4-13.el6_8.2
spice (Red Hat package) - update to 0.12.4-20.el7_3
spice - addressed in versions 0.12.8-2.fc24, 0.13.3-2.fc25
rhevm-appliance (Red Hat package) - update to 4.0.20170307.0-1.el7ev

External References

Related Security Bulletins