Buffer overflow in SPICE - CVE-2015-3247

 

Buffer overflow in SPICE - CVE-2015-3247

Published: September 8, 2015 / Updated: August 3, 2020


Vulnerability identifier: #VU33273
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2015-3247
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability: No public exploit available
Vendor: SPICE
Affected software:
SPICE

Detailed vulnerability description

The vulnerability allows a local non-authenticated attacker to execute arbitrary code.

Race condition in the worker_update_monitors_config function in SPICE 0.12.4 allows a remote authenticated guest user to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) or possibly execute arbitrary code on the host via unspecified vectors.


How to mitigate CVE-2015-3247

Install update from vendor's website.

Sources