CVE-2018-10893

Severity CVSS v4.0:
Pending analysis
Type:
CWE-122 Heap-based Buffer Overflow
Publication date:
11/09/2018
Last modified:
12/02/2023

Description

Multiple integer overflow and buffer overflow issues were discovered in spice-client's handling of LZ compressed frames. A malicious server could cause the client to crash or, potentially, execute arbitrary code.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:spice_project:spice:-:*:*:*:*:*:*:*