Multiple integer overflow and buffer overflow issues were discovered in spice-client's handling of LZ compressed frames. A malicious server could cause the client to crash or, potentially, execute arbitrary code.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2018-09-11T15:00:00

Updated: 2020-02-11T12:06:05

Reserved: 2018-05-09T00:00:00


Link: CVE-2018-10893

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2018-09-11T15:29:00.233

Modified: 2023-02-12T23:31:44.797


Link: CVE-2018-10893

JSON object: View

cve-icon Redhat Information

No data.