Logo
componentspice
Name
spice
Version
0.16.0
Type
library
Description
Simple Protocol for Independent Computing Environments
Licenses
LGPL-2.1-or-later
PURL
-
CPE
cpe:2.3:*:spice_project:spice:0.16.0:*:*:*:*:*:*:*

Other Versions#


Project
Branch
Version
kirkstone
0.14.2+gitX
scarthgap
0.15.2

Patches#


#
Title
Author
Resolve
1
test-gst: Fix compilation error
Frediano Ziglio <freddy77@gmail.com>
2
test-display-base.cpp: adjust designated init for C++20
Nicholas Vinson <nvinson234@gmail.com>

Vulnerabilities#


Name
Analysis
Description
Not Affected
Multiple integer overflow and buffer overflow issues were discovered in spice-client's handling of LZ compressed frames. A malicious server could cause the client to crash or, potentially, execute arbitrary code.
Not Affected
SPICE allows local guest OS users to read from or write to arbitrary host memory locations via crafted primary surface parameters, a similar issue to CVE-2015-5261.
Not Affected
The smartcard interaction in SPICE allows remote attackers to cause a denial of service (QEMU-KVM process crash) or possibly execute arbitrary code via vectors related to connecting to a guest VM, which triggers a heap-based buffer overflow.