CVE-2013-4130

Severity CVSS v4.0:
Pending analysis
Type:
CWE-399 Resource Management Errors
Publication date:
20/08/2013
Last modified:
11/04/2025

Description

The (1) red_channel_pipes_add_type and (2) red_channel_pipes_add_empty_msg functions in server/red_channel.c in SPICE before 0.12.4 do not properly perform ring loops, which might allow remote attackers to cause a denial of service (reachable assertion and server exit) by triggering a network error.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:spice_project:spice:*:*:*:*:*:*:*:* 0.12.3 (including)
cpe:2.3:a:spice_project:spice:0.5.2:*:*:*:*:*:*:*
cpe:2.3:a:spice_project:spice:0.5.3:*:*:*:*:*:*:*
cpe:2.3:a:spice_project:spice:0.6.0:*:*:*:*:*:*:*
cpe:2.3:a:spice_project:spice:0.6.1:*:*:*:*:*:*:*
cpe:2.3:a:spice_project:spice:0.6.2:*:*:*:*:*:*:*
cpe:2.3:a:spice_project:spice:0.6.3:*:*:*:*:*:*:*
cpe:2.3:a:spice_project:spice:0.6.4:*:*:*:*:*:*:*
cpe:2.3:a:spice_project:spice:0.7.0:*:*:*:*:*:*:*
cpe:2.3:a:spice_project:spice:0.7.1:*:*:*:*:*:*:*
cpe:2.3:a:spice_project:spice:0.7.2:*:*:*:*:*:*:*
cpe:2.3:a:spice_project:spice:0.7.3:*:*:*:*:*:*:*
cpe:2.3:a:spice_project:spice:0.8.0:*:*:*:*:*:*:*
cpe:2.3:a:spice_project:spice:0.8.1:*:*:*:*:*:*:*
cpe:2.3:a:spice_project:spice:0.8.2:*:*:*:*:*:*:*