CVE-2017-12194

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
14/03/2018
Last modified:
17/06/2019

Description

A flaw was found in the way spice-client processed certain messages sent from the server. An attacker, having control of malicious spice-server, could use this flaw to crash the client or execute arbitrary code with permissions of the user running the client. spice-gtk versions through 0.34 are believed to be vulnerable.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:spice-gtk_project:spice-gtk:*:*:*:*:*:*:*:* 0.34 (including)