Vulnerability Name: | CVE-2013-4130 (CCN-85866) | ||||||||||||||||||||||||||||||||||||||||
Assigned: | 2013-07-05 | ||||||||||||||||||||||||||||||||||||||||
Published: | 2013-07-05 | ||||||||||||||||||||||||||||||||||||||||
Updated: | 2014-01-24 | ||||||||||||||||||||||||||||||||||||||||
Summary: | The (1) red_channel_pipes_add_type and (2) red_channel_pipes_add_empty_msg functions in server/red_channel.c in SPICE before 0.12.4 do not properly perform ring loops, which might allow remote attackers to cause a denial of service (reachable assertion and server exit) by triggering a network error. | ||||||||||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
| ||||||||||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
3.2 Low (REDHAT Temporal CVSS v2 Vector: AV:A/AC:H/Au:S/C:N/I:N/A:C/E:U/RL:OF/RC:C)
| ||||||||||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-399 | ||||||||||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||||||||||||||||||||||||||||||
References: | Source: CCN Type: spice Web Site spice Source: CCN Type: spice Repository Web Site spice Repository Source: CONFIRM Type: Patch http://cgit.freedesktop.org/spice/spice/commit/?id=53488f0275d6c8a121af49f7ac817d09ce68090d Source: MITRE Type: CNA CVE-2013-4130 Source: CCN Type: RHSA-2013-1192 Moderate: spice-server security update Source: CCN Type: RHSA-2013-1260 Moderate: rhev-hypervisor6 security and bug fix update Source: REDHAT Type: UNKNOWN RHSA-2013:1260 Source: MLIST Type: UNKNOWN [oss-security] 20130715 Re: CVE Request -- spice: unsafe clients ring access abort Source: DEBIAN Type: UNKNOWN DSA-2839 Source: CCN Type: BID-61192 SPICE CVE-2013-4130 Multiple Denial of Service Vulnerabilities Source: UBUNTU Type: UNKNOWN USN-1926-1 Source: CCN Type: Red Hat Bugzilla Bug 984769 CVE-2013-4130 spice: unsafe clients ring access abort Source: CONFIRM Type: UNKNOWN https://bugzilla.redhat.com/show_bug.cgi?id=984769 Source: XF Type: UNKNOWN spice-cve20134130-redchannel-dos(85866) Source: CCN Type: WhiteSource Vulnerability Database CVE-2013-4130 | ||||||||||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration RedHat 1: Configuration RedHat 2: Configuration RedHat 3: Configuration RedHat 4: Configuration RedHat 5: Configuration CCN 1: ![]() | ||||||||||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||
BACK |