Buffer overflow - CVE-2017-7506
Published: July 12, 2017 / Updated: July 17, 2017
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to boundary error when processing SPICE protocol client messages in spice. A remote unauthenticated attacker can send a specially crafted message, trigger buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.